If you find a security vulnerability in Popplio, please report it privately to security@nodebyte.co.uk. Do not open a public GitHub issue for security reports or via GitHubs internal methods.
Include as much of the following as you can:
- A description of the vulnerability and its potential impact.
- Steps to reproduce it, including any proof-of-concept code.
- The URL or endpoint affected.
- Your assessment of severity, if you have one.
We'll acknowledge your report within 3 business days and aim to give you a more detailed response, including our planned next steps, within 10 business days.
This policy covers:
- spider.omniplex.gg (production)
- spider-staging.omniplex.gg (staging)
- The source code in this repository
Vulnerabilities in third-party services we depend on (Discord's API, our CDN provider, and so on) should be reported to those providers directly, unless the issue is in how we integrate with them.
- Vulnerabilities that require physical access to a user's device.
- Social engineering of staff, contributors, or users.
- Denial-of-service attacks or anything that degrades service for other users.
- Automated scanning that generates significant traffic without prior coordination with us.
- Reports for outdated browsers or unsupported platforms.
We ask that you give us a reasonable amount of time to investigate and fix a reported vulnerability before disclosing it publicly. We'll keep you updated as we work on a fix and credit you in the disclosure, if you'd like, once it's resolved.
We won't pursue legal action against anyone who reports a vulnerability in good faith, follows this policy, and avoids privacy violations, data destruction, or service disruption while investigating.