Security Policy — EOLkits

Supported Versions

VersionSupported
Latest release✅ Yes
All previous❌ No (upgrade to latest)

Reporting Security Vulnerabilities

Please do not file public issues for security vulnerabilities.

Instead:

  1. Open a private vulnerability report on GitHub:
  1. Or contact via GitHub Discussions with "[SECURITY]" prefix

Expected response time: 48 hours

Security Measures

Code

Infrastructure

GitHub App

Bug Bounty

Status: Active (in-system credits only, no cash pre-revenue)

SeverityReward
Critical (RCE, data breach)$1,499 Audit credit
High (Auth bypass, SSRF)$599 Audit credit
Medium (XSS, info disclosure)$299 Audit credit
Low (Best practice)GitHub mention

Scope:

Out of scope:

Safe Harbor

We support safe harbor for security researchers:

Security Checklist for Users

Incident History

DateIncidentStatus
None yet--

*This security policy follows coordinated disclosure principles.*