Skip to content

Security: AmadeusITGroup/SmartErrorHandler

Security

SECURITY.md

Security Policy

This repository is currently in an internal-review phase and is not yet publicly published.

Supported Versions

Security fixes are applied to the active development line (dev) and included in the next release cut to main.

Reporting a Vulnerability

Please do not report security vulnerabilities in public issues.

Report vulnerabilities privately to:

Please include:

  • A clear description of the issue
  • Reproduction steps or proof of concept
  • Potential impact and affected component (frontend/backend)
  • Suggested mitigation (if available)

Response SLA

Internal-review phase (current)

  • Acknowledgement target: within 5 business days
  • Triage target: within 10 business days
  • Mitigation or remediation plan: within 30 calendar days

Public phase (post-publication)

  • Acknowledgement target: within 3 business days
  • Triage target: within 7 business days
  • Mitigation or remediation plan: within 21 calendar days

These are target timelines and may vary based on severity and complexity.

Disclosure Policy

  • Coordinated disclosure is requested.
  • We may delay public disclosure until a fix or mitigation is available.
  • Once resolved, disclosure details may be included in release notes.

There aren't any published security advisories