Security Policy
At SBOMix, we take security seriously. This page outlines our vulnerability disclosure policy and how to report security issues responsibly.
Reporting a Vulnerability
If you discover a security vulnerability in SBOMix, please report it responsibly by contacting our security team:
Please do not:
- Publicly disclose the vulnerability before we've had time to address it
- Open a public GitHub issue for security vulnerabilities
- Post about the vulnerability on social media
What to Include in Your Report
To help us address the issue quickly, please include the following information:
- Clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact and severity
- Your contact information (email or GitHub handle)
- Any proof-of-concept code (if applicable)
Our Response Timeline
- Within 48 hours: We acknowledge receipt of your report
- Within 7 days: We provide an initial assessment and timeline for a fix
- Within 90 days: We release a patch or security update
- Upon release: We credit you in our security acknowledgments (if you wish)
Security Acknowledgments
We recognize and appreciate security researchers who report vulnerabilities responsibly. Those who wish to be acknowledged will be listed on our Security Acknowledgments page.
Security Best Practices
When using SBOMix, we recommend:
- Keep SBOMix updated to the latest version
- Review generated SBOMs for accuracy before relying on them
- Use HTTPS for all API communications
- Rotate API keys regularly
- Monitor your SBOMix dashboard for security alerts
- Report any suspicious activity to our security team
Scope
This policy applies to:
- The SBOMix CLI tool (open source)
- The SBOMix hosted platform (api.sbomix.com)
- The SBOMix GitHub Action
- All official SBOMix repositories and services
This policy does not apply to:
- Third-party services or integrations
- User-created content or configurations
- Issues in dependencies or upstream projects
Responsible Disclosure
We follow responsible disclosure practices and expect security researchers to do the same. This means:
- Give us reasonable time to fix the issue before public disclosure
- Avoid accessing or modifying data you don't own
- Don't disrupt the service or harm other users
- Work with us to understand and verify the vulnerability
Security.txt
Our security contact information is also available in our security.txt file at /.well-known/security.txt, which follows the RFC 9116 standard.
Questions?
If you have questions about this security policy, please contact security@sbomix.com.