Skip to content

Security: OsbornePro/NovaKey-Runner

SECURITY.md

Security Policy

πŸ” Security for NovaKey-Runner

The NovaKey-Runner project takes security seriously. We appreciate the efforts of security researchers and users who help keep this project safe and trustworthy.

πŸ“£ Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public GitHub issue.

Instead, report it responsibly using one of the following methods:

  • GitHub Security Advisories (preferred):
    Go to the repository β†’ Security tab β†’ Report a vulnerability
  • Email: security@novakey.dev
    (Replace this with the correct address if different.)

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Any relevant logs, screenshots, or proof-of-concept code

⏱️ Response Timeline

We aim to:

  • Acknowledge reports within 72 hours
  • Provide an initial assessment within 7 days
  • Release a fix as soon as reasonably possible, depending on severity

πŸ›‘οΈ Supported Versions

Only the latest release of NovaKey-Runner is actively supported with security updates.

Version Supported
Latest βœ… Yes
Older ❌ No

🀝 Coordinated Disclosure

We kindly request that you:

  • Give us reasonable time to investigate and fix the issue
  • Avoid public disclosure until a fix or mitigation is available

We’re happy to credit reporters for valid disclosures, unless anonymity is preferred.

🚫 Out of Scope

The following are generally considered out of scope:

  • Denial-of-service attacks
  • Vulnerabilities requiring physical access
  • Issues in third-party dependencies without a demonstrated exploit in this project

πŸ™ Thanks

Thank you for helping make NovaKey-Runner more secure. Responsible disclosure helps everyone.

β€” The NovaKey Team

There aren’t any published security advisories