Skip to content

Security: h46373824-tech/offerPilot-AI

SECURITY.md

Security Policy

Supported version

Version Supported
1.0.1 Yes
Earlier versions No

Security fixes are prepared on dev and included in the next tagged release. Users should run the latest stable version whenever possible.

Reporting a vulnerability

Do not open a public Issue for authentication bypasses, SSRF, data exposure, malicious file handling, dependency exploits, or leaked credentials. Use GitHub's private vulnerability reporting for this repository:

https://github.com/h46373824-tech/offerPilot-AI/security/advisories/new

Include the affected version, reproduction steps, impact, and any suggested mitigation. Do not include real resumes, access tokens, passwords, or applicant data. Maintainers should acknowledge a complete report within seven days and coordinate disclosure after a fix is available.

Data-source incidents

If an official recruitment source requests removal, changes its terms, exposes private information, or begins requiring access-control bypasses, disable that source immediately and report it through the same private channel.

There aren't any published security advisories