Skip to content

Security: codberce/iabacu

SECURITY.md

Security policy

Supported version

Security fixes are applied to the latest code on the default branch. Older commits, forks, and third-party deployments are not maintained by this project.

Reporting a vulnerability

Please use Report a vulnerability on the repository's Security tab to send a private report. Do not open a public issue, pull request, or discussion for an undisclosed vulnerability.

Include the affected route or component, reproduction steps, impact, and any suggested mitigation. Remove real credentials, personal data, student work, and other sensitive information from evidence. We aim to acknowledge a report within seven days and will coordinate disclosure after a fix is available.

Examples in scope include exposed secrets, injection, cross-site scripting, unsafe file handling, malicious archives, and accidental disclosure of work sent to the configured AI provider.

Incorrect educational content and ordinary bugs are not security issues; use a regular issue for those. Reports about an AI provider should also be sent to that provider when the flaw is in its service rather than in this repository.

There aren't any published security advisories