Please report security vulnerabilities privately through GitHub. Go to the Security tab of this repository and click Report a vulnerability, or use this direct link:
https://github.com/arnowelzel/drawio-nextcloud/security/advisories/new
Please do not open a public issue for security vulnerabilities.
This policy covers the Nextcloud integration code in this repository (PHP backend, JavaScript frontend, configuration handling). The draw.io editor itself is maintained separately by JGraph at jgraph/drawio - please report any draw.io editor vulnerabilities there.
This repository is not covered by the JGraph SOC 2 process. JGraph does not maintain this app and does not provide commercial services or support for this app.