If you discover a security vulnerability in this repository, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, email: security@hummbl.io
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: within 48 hours
- Initial assessment: within 7 days
- Fix or mitigation: depends on severity
This policy covers the code in this repository only. For vulnerabilities in dependencies, report to the upstream maintainer.