Skip to content

Security: GC-Stats/OpenData

Security

SECURITY.md

Security Policy — GC-Stats

Supported Versions

Only the latest version of each repository is actively maintained and eligible for security fixes.

Repository Supported
GC-Stats-Website ✅ Latest
GC-Stats-DiscordBot ✅ Latest
GC-Stats-API ✅ Latest
GC-Stats-OpenData ✅ Latest

Reporting a Vulnerability

We take security vulnerabilities seriously, especially those involving user data (discord_id, val_id).

Please do NOT open a public GitHub issue for security vulnerabilities.

You can report a vulnerability through either of the following channels:

📧 Email

Send a detailed report to security@gc-stats.app

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact (data exposure, unauthorized access, etc.)
  • Any relevant logs, screenshots, or proof-of-concept code

🔒 GitHub Private Vulnerability Reporting

Use the Report a vulnerability button available in the Security tab of the relevant repository.


What to Expect

We will acknowledge receipt of your report as soon as possible and keep you informed as we investigate and address the issue. We do not commit to a fixed response deadline, but we are committed to handling reports seriously and transparently.

Once a fix is deployed, we will credit you in the Hall of Fame below (unless you prefer to remain anonymous).


Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to investigate and patch the issue before any public disclosure.
  • Avoid accessing, modifying, or deleting user data beyond what is strictly necessary to demonstrate the vulnerability.
  • Do not exploit the vulnerability for any purpose other than verification.

We commit on our end to not take legal action against researchers acting in good faith under these guidelines.


Hall of Fame

We sincerely thank the following researchers for their responsible disclosures:

No entries yet — you could be the first!


GC-Stats Security Policy v1.0 — Alice Alleman — 2026

There aren't any published security advisories