Skip to content

Security: fazel-studio/vetour

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x

Reporting a Vulnerability

If you discover a security vulnerability within Vetour, please report it privately via email to the project maintainer. Do not disclose vulnerabilities publicly until they have been addressed.

To report a vulnerability:

  1. Email the maintainer at the address listed in the profile.
  2. Include a detailed description of the vulnerability.
  3. Provide steps to reproduce the issue.
  4. If possible, include a proof of concept.

You can expect an acknowledgment within 48 hours, and a detailed response within 5 business days regarding the next steps.

Scope

Security issues include, but are not limited to:

  • Remote code execution
  • Arbitrary file read/write via the application
  • Injection vulnerabilities
  • Authentication bypass (for the deploy feature)
  • Unsafe deserialization

Non-Qualifying Issues

The following are not considered security vulnerabilities:

  • Missing security headers in development mode
  • Dependency vulnerabilities in outdated packages (please update instead)
  • Features explicitly disabled in the open-source build (see README)

Preferred Encryption

If possible, please encrypt sensitive vulnerability reports using the maintainer's PGP key (if available).

We appreciate your help in keeping Vetour and its users safe.

There aren't any published security advisories