Skip to content

Security: ocucor/dotreport

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue in DotReport, please do not open a public issue.

Instead, report it privately through GitHub's Report a vulnerability feature or contact me directly through Discord (@ottergrl.) or email (yy@deranged.network).

Please include as much information as possible:

  • A description of the issue.
  • Steps to reproduce it.
  • The potential impact.
  • Any suggested fix, if you have one.

I will acknowledge reports as soon as reasonably possible and work toward a fix if the issue is confirmed.

Scope

This project does not publish compiled binaries or official releases. Users are expected to build the application from source.

Security reports are most helpful when they involve issues in the project's source code, server-side behavior, configuration handling, or dependency usage.

Supported Versions

Because the project does not maintain versioned releases, security fixes are applied to the current main branch.

If a vulnerability is fixed, users should update to the latest commit.

There aren't any published security advisories