Skip to content

Security: Gurubase/gurubase

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

At Gurubase, we take security seriously. If you believe you have found a security vulnerability, please report it to us as described below.

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via email to:

Please include the following information in your report:

  • Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Response Policy

We strive to:

  • Respond to security reports within 2 business days
  • Release patches for verified security vulnerabilities within 30 days
  • Keep reporters informed about our progress

Security Updates

Security updates will be released through our normal release channels. We strongly recommend keeping Gurubase updated with the latest security patches.

There aren’t any published security advisories