Skip to content

Security: ravenbix/IntegrationServicesTools

SECURITY.md

Security Policy

Reporting a security vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report them privately through GitHub's built-in private vulnerability reporting:

  1. Go to the Security tab of this repository.
  2. Click Report a vulnerability.
  3. Complete the advisory form with the details below.

This opens a private channel visible only to the maintainers.

What to include

To help us understand the nature and scope of the issue, please include as much of the following as you can:

  • The type of issue (for example: command injection, credential exposure, insecure deserialization).
  • The affected command(s) or source file path(s).
  • The version of IntegrationServicesTools and of Windows PowerShell you are running.
  • Step-by-step instructions to reproduce the issue.
  • Proof-of-concept code, if available.
  • The impact of the issue, including how it might be exploited.

This information helps us triage your report more quickly.

What to expect

  • We will acknowledge your report as soon as we are able and keep you informed of progress toward a fix. This is a community-maintained project, so we cannot commit to a fixed response time.
  • We ask that you practice coordinated (responsible) disclosure: give us a reasonable opportunity to release a fix before disclosing the issue publicly.
  • We will credit you for the discovery when the fix is published, unless you prefer otherwise.

Supported versions

Security fixes are applied to the latest published release of IntegrationServicesTools. Older versions are not maintained.

Version Supported
Latest release
Older releases

Maintainer note (repository setup)

Private vulnerability reporting must be enabled for the channel above to appear: Settings -> Code security -> Private vulnerability reporting -> Enable. Until then, contact the maintainer privately through GitHub.

There aren't any published security advisories