Skip to content

Security: mteu/sbom-parser

SECURITY.md

Security Policy

Please follow the guidelines below if you believe you have discovered a vulnerability in this project.

Caution

Please do not open GitHub issues for security vulnerabilities!

Reporting a Vulnerability

Please use GitHub's private vulnerability reporting. Open the Security tab and click "Report a vulnerability", or go straight to the report form.

Your report should include the following details:

  • The exact version or version range that you analysed.
  • The PHP version that you used for your analysis.
  • A step-by-step explanation of how to exploit the potential vulnerability.

What to Expect

One person maintains this project in their spare time. Expect a first reply within 14 days. You will hear whether the report is accepted and when a fix is planned. No bounties are offered.

There aren't any published security advisories