Skip to content

Security: PlexiOSS/Popplio

SECURITY.md

Security Policy

Reporting a vulnerability

If you find a security vulnerability in Popplio, please report it privately to security@nodebyte.co.uk. Do not open a public GitHub issue for security reports or via GitHubs internal methods.

Include as much of the following as you can:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce it, including any proof-of-concept code.
  • The URL or endpoint affected.
  • Your assessment of severity, if you have one.

We'll acknowledge your report within 3 business days and aim to give you a more detailed response, including our planned next steps, within 10 business days.

Scope

This policy covers:

Vulnerabilities in third-party services we depend on (Discord's API, our CDN provider, and so on) should be reported to those providers directly, unless the issue is in how we integrate with them.

Out of scope

  • Vulnerabilities that require physical access to a user's device.
  • Social engineering of staff, contributors, or users.
  • Denial-of-service attacks or anything that degrades service for other users.
  • Automated scanning that generates significant traffic without prior coordination with us.
  • Reports for outdated browsers or unsupported platforms.

Disclosure

We ask that you give us a reasonable amount of time to investigate and fix a reported vulnerability before disclosing it publicly. We'll keep you updated as we work on a fix and credit you in the disclosure, if you'd like, once it's resolved.

Safe harbor

We won't pursue legal action against anyone who reports a vulnerability in good faith, follows this policy, and avoids privacy violations, data destruction, or service disruption while investigating.

Learn more about advisories related to PlexiOSS/Popplio in the GitHub Advisory Database