If you discover a security issue in MyNextHome, please report it privately to prevent exploitation before a fix is implemented.
- Email: info@daraza.net
- GitHub Security Advisory: Submit a confidential report
Please provide:
- A clear description of the issue.
- Steps to reproduce the vulnerability.
- Any potential impact it may have.
- Your contact information for follow-ups.
We aim to acknowledge reports within 48 hours and resolve critical issues within 7 days.
We support security updates for the following versions:
| Version | Supported |
|---|---|
| Latest | ✅ Yes |
| Previous | ✅ Yes (minor fixes) |
| Older | ❌ No (upgrade recommended) |
To ensure a secure environment, we recommend:
- Keeping Django, GeoDjango, and dependencies updated.
- Using strong passwords and enabling multi-factor authentication (MFA).
- Restricting database access to trusted sources.
- Regularly reviewing logs for unusual activity.
- Enforcing HTTPS and Content Security Policies (CSP).
We follow a responsible disclosure policy: if you find a vulnerability, please report it privately before making it public to allow us time to fix it.
Thank you for helping us keep MyNextHome secure! 🔒