Skip to content

Security: Apinor/web

Security

SECURITY.md

Security Policy for apinor/web

Reporting a Vulnerability

πŸ›‘οΈ We take security seriously! If you discover a security vulnerability in our project, please report it responsibly.

How to Report

What to Include

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Affected versions (if applicable)
  • Suggested mitigation (optional but appreciated)

Response Time

  • We aim to acknowledge reports within 48 hours
  • Critical issues will be prioritized for resolution

Supported Versions

βœ… Actively maintained branches receive security updates:

Branch Supported Status
main βœ… Stable releases
Any other brances ❌ Not supported
Legacy ❌ No longer supported

Security Updates

πŸ”’ Our update process:

  1. Regular dependency scanning using Dependabot
  2. Monthly security audits
  3. Critical vulnerabilities patched within 72 hours of confirmation
  4. All security updates documented in CHANGELOG.md

Dependency Management

πŸ“¦ Third-party components:

  • All dependencies are pinned to specific versions
  • Automated vulnerability scanning using GitHub Actions
  • Regular dependency updates every 2 weeks

Access Control

πŸ”‘ Repository permissions:

  • Maintainers: 2 required for sensitive operations
  • Least privilege principle enforced
  • All contributors must enable 2FA
  • API keys/tokens never committed to version control

Incident Response

🚨 Our response protocol:

  1. Immediate investigation of reported issues
  2. Containment of affected systems
  3. Root cause analysis
  4. Patch deployment
  5. Transparent communication to users

Security Best Practices

πŸ’‘ For contributors:

  • Follow OWASP Top 10 guidelines
  • All code changes require security review
  • Never hardcode credentials
  • Use parameterized queries to prevent SQLi
  • Validate all user input

Disclaimer

❗ This policy may evolve as the project grows. Last updated: 2023-09-15


Security Status

There aren’t any published security advisories