Skip to content

Security: intrusus-dev/xql-hub

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in XQL Hub, please report it responsibly:

  1. Report the security vulnerability only via the Security Tab in this repository. Do not create a public issue.
  2. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

We will respond within 48 hours and work with you to address the issue.

Query Security

When contributing queries, please ensure:

  • No hardcoded credentials or API keys
  • No internal IP addresses or hostnames
  • No customer-specific data
  • No proprietary detection logic that shouldn't be public

Responsible Disclosure

We follow responsible disclosure practices:

  • We will acknowledge receipt within 48 hours
  • We will provide a timeline for fixes
  • We will credit researchers (unless anonymity is requested)

There aren’t any published security advisories