Only the latest version of each repository is actively maintained and eligible for security fixes.
| Repository | Supported |
|---|---|
| GC-Stats-Website | ✅ Latest |
| GC-Stats-DiscordBot | ✅ Latest |
| GC-Stats-API | ✅ Latest |
| GC-Stats-OpenData | ✅ Latest |
We take security vulnerabilities seriously, especially those involving user data (discord_id, val_id).
Please do NOT open a public GitHub issue for security vulnerabilities.
You can report a vulnerability through either of the following channels:
Send a detailed report to security@gc-stats.app
Please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The potential impact (data exposure, unauthorized access, etc.)
- Any relevant logs, screenshots, or proof-of-concept code
Use the Report a vulnerability button available in the Security tab of the relevant repository.
We will acknowledge receipt of your report as soon as possible and keep you informed as we investigate and address the issue. We do not commit to a fixed response deadline, but we are committed to handling reports seriously and transparently.
Once a fix is deployed, we will credit you in the Hall of Fame below (unless you prefer to remain anonymous).
We kindly ask that you:
- Give us reasonable time to investigate and patch the issue before any public disclosure.
- Avoid accessing, modifying, or deleting user data beyond what is strictly necessary to demonstrate the vulnerability.
- Do not exploit the vulnerability for any purpose other than verification.
We commit on our end to not take legal action against researchers acting in good faith under these guidelines.
We sincerely thank the following researchers for their responsible disclosures:
No entries yet — you could be the first!
GC-Stats Security Policy v1.0 — Alice Alleman — 2026