Skip to content

Latest commit

 

History

History
50 lines (31 loc) · 2.17 KB

SECURITY.md

File metadata and controls

50 lines (31 loc) · 2.17 KB

Security Policy

Supported Version

We only support the latest deployed version of our frontend application, which can be found here.

Reporting a Vulnerability

If you discover a security vulnerability, please report it to us. We take all security vulnerabilities seriously and will address them promptly.

How to Report

  1. GitHub Security Advisories: Report the vulnerability via our GitHub Security Advisories page.
  2. Details: Include as much information as possible about the vulnerability. This should include:
    • Steps to reproduce the vulnerability
    • Potential impact of the vulnerability
    • Any possible fixes or workarounds

Response Process

  • We will acknowledge your report within 48 hours.
  • We will investigate the issue and provide an initial response within 5 business days.
  • We aim to provide a fix for the vulnerability promptly, typically within 30 days.

Public Disclosure

We will publish a summary of the vulnerability and its resolution once the fix has been deployed. If you prefer, we will credit you with the discovery of the vulnerability.

Our Security Measures

To ensure the security of our frontend application, we use the following tools and practices:

  • Depfu: Automated dependency updates.
  • Dependabot: Alerts us to potential security vulnerabilities in our dependencies.
  • GitHub Code Scanning: Identifies potential security vulnerabilities in our codebase.
  • GitHub Secret Scanning: Detects and alerts on the presence of secrets within our repository.

Preview Deployments

We use preview deployments for pull requests to facilitate testing and review. These previews are not fully supported versions but aid in assessing changes before deploymen

Resources

For further queries or concerns, please contact us via email

Thank you for helping us keep our application secure!