Skip to content

Security: MobiDev-Org/treegress-browser-core

Security

SECURITY.md

Security

Security of Treegress Browser Core is handled by Treegress maintainers.

Reporting security issues

Do not report security vulnerabilities in public issues.

Preferred channel:

  1. Open a private vulnerability report via GitHub Security Advisories in this repository (Security -> Report a vulnerability).

If private reporting is unavailable in your environment, contact repository maintainers directly and avoid posting exploit details publicly.

What to include

Please include as much of the following as possible:

  • vulnerability type
  • affected files/paths
  • affected branch/tag/commit
  • reproduction steps
  • proof of concept (if available)
  • impact and attack scenario
  • suggested mitigation (if known)

Disclosure policy

We follow coordinated vulnerability disclosure:

  • report privately first
  • allow maintainers to investigate and patch
  • publish details only after a fix is available or a coordinated disclosure date is agreed

There aren't any published security advisories