Skip to content

Security: domternal/self-hosting

SECURITY.md

Security Policy

Scope

This policy covers the MIT reference servers in this repository (the collaboration server and the AI proxy) and their third-party dependencies. Neither server installs a Domternal Pro package. If you copied this repository as a template for your own deployment, replace this file with your deployment's own reporting channel: Domternal cannot fix or even see your fork.

Reporting a Vulnerability

Please do not report security vulnerabilities through the public issue tracker. A public security issue is an exploit announcement for every deployment that has not patched yet.

Email security@domternal.dev.

Please include:

  • A description of the vulnerability and its impact
  • Steps to reproduce, ideally with a minimal example
  • Whether it affects a server in this repository or an installed package, and the release tag or full Git commit SHA

Security reports are read with priority. Please allow time for a fix to reach deployments before any public disclosure.

Ordinary defects

Defects that are not security issues are welcome on the issue tracker.

There aren't any published security advisories