Skip to content

Security: BenchFinity/Workbench

Security

SECURITY.md

Security Policy

Supported Versions

Benchfinity is pre-1.0 software. Security fixes are applied to the active development line on develop and to the latest published release when one exists.

Reporting a Vulnerability

Do not report security vulnerabilities in public issues.

Use GitHub private vulnerability reporting if it is available for this repository, or contact the maintainer directly through the repository owner profile.

Please include:

  • A description of the vulnerability.
  • Steps to reproduce it.
  • The affected version, branch, or commit.
  • Any known impact or workaround.

The maintainer will acknowledge valid reports as quickly as practical and coordinate a fix before public disclosure.

Security Expectations

  • Do not commit secrets, tokens, credentials, or private project files.
  • Do not include sensitive printer, account, or artifact data in logs.
  • Keep dependency audit findings at zero before release handoff.

There aren't any published security advisories