Skip to content

Security: invoicetronic/desk

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Invoicetronic Desk, please report it responsibly.

Do not open a public GitHub issue.

Instead, email info@invoicetronic.com with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 5 business days
  • Fix or mitigation: as soon as possible, depending on severity

Supported Versions

Version Supported
1.x Yes
< 1.0 No

Disclosure Policy

We follow coordinated disclosure. Once a fix is released, we will:

  1. Publish a GitHub Security Advisory
  2. Credit the reporter (unless they prefer anonymity)
  3. Include details in the changelog

There aren't any published security advisories