Skip to content

Security: gnueole/jobby-md2html

Security

SECURITY.md

Security Policy

Author: Julien (Éole) Avarre (hi@eole.me)

We take the security of Jobby seriously. If you believe you have found a security vulnerability, please report it to us privately so we can resolve it before public disclosure.

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities. Instead, report them privately using one of the following methods:

  1. Email: Send a detailed report to hi+jobby@eole.me (Julien Avarre).
  2. GitHub Security Advisory: Submit a private advisory request directly on the GitHub repository at https://github.com/gnueole/jobby-md2html/security/advisories/new.

What to Include in a Report

  • A description of the vulnerability and its potential impact.
  • Detailed steps to reproduce the issue (including any proofs of concept, sample requests, or payload scripts).
  • Any recommended fixes or mitigations if you have them.

Our Response Process

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours.
  • Triage: We will investigate the issue and coordinate with you on confirmation and timeline.
  • Resolution: If confirmed, we will develop a patch and release an update. We ask that you give us reasonable time to fix the issue before public disclosure.

🔗 Jobby Project Links

  • README - Project overview, architecture, directives and guide.
  • Installation Guide - Learn how to set up Jobby locally or via Docker.
  • Changelog - Review releases and change history.
  • License - View the MIT License terms.

There aren't any published security advisories