Skip to content

Security: sebastian-software/ardo

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability in Ardo, please report it responsibly.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via email to:

security@sebastian-software.de

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution Target: Within 30 days (depending on complexity)

After Reporting

  1. We will acknowledge your report within 48 hours
  2. We will investigate and keep you informed of our progress
  3. Once fixed, we will publicly disclose the vulnerability with credit to you (unless you prefer to remain anonymous)

Security Best Practices for Users

When using Ardo in your projects:

  • Keep Ardo and its dependencies up to date
  • Review any custom MDX components for potential XSS vulnerabilities
  • Use environment variables for sensitive configuration
  • Follow the principle of least privilege for deployment

Acknowledgments

We appreciate the security research community and will acknowledge reporters in our release notes (with permission).

Thank you for helping keep Ardo and its users safe!

There aren’t any published security advisories