Skip to content

Security: AIS-Commercial-Business-Unit/RiskInsure

Security

SECURITY.md

Security Policy

Supported Versions

This section describes which versions of the RiskInsure project are currently being supported with security updates.

Version Supported
Latest

Reporting a Vulnerability

We take the security of RiskInsure seriously. If you believe you have found a security vulnerability, please report it to us as described below.

Please do not report security vulnerabilities through public GitHub issues.

How to Report a Security Vulnerability

  1. Email: Send an email to your organization's security team with details of the vulnerability
  2. Include:
    • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
    • Full paths of source file(s) related to the manifestation of the issue
    • The location of the affected source code (tag/branch/commit or direct URL)
    • Any special configuration required to reproduce the issue
    • Step-by-step instructions to reproduce the issue
    • Proof-of-concept or exploit code (if possible)
    • Impact of the issue, including how an attacker might exploit it

What to Expect

  • You should receive an acknowledgment within 48 hours
  • We will investigate and provide updates on the progress
  • We will notify you when the vulnerability has been fixed
  • We may ask for additional information or guidance during the resolution process

Security Best Practices

When contributing to this project, please:

  • Never commit secrets, API keys, or credentials
  • Use secure dependencies and keep them updated
  • Follow secure coding practices
  • Run security scans before submitting pull requests
  • Enable two-factor authentication on your GitHub account

Security Updates

Security updates will be released as needed. Users should update to the latest version to ensure they have all security patches.

There aren’t any published security advisories