Skip to content

Security: dbsystel/cdk-sops-secrets

Security

.github/SECURITY.md

Security Policy

Supported Versions

We release patches for the latest major.minor version.

Reporting a Vulnerability

Please report security issues via GitHub Security Advisories ("Report a vulnerability" in the repository Security tab) or e-mail the CODEOWNERS directly. DO NOT open an issue.

Dependency Management

We use Renovate to automatically keep dependencies up to date. Routine updates are merged only after a 3-day delay ("cool-down") to reduce supply-chain risk from freshly compromised releases. High or critical severity vulnerabilities may be upgraded immediately; feel free to open an issue if urgent remediation is needed or if an automatic PR has not appeared.

Public Disclosure

We kindly request you avoid public disclosure until a fix is available. We will coordinate a CVE if appropriate.

There aren’t any published security advisories