Skip to content

Security: px-pole/Ivenn

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not publish security vulnerabilities, private data exposures, or potential data-loss issues in a public GitHub issue. Report them privately to the repository maintainers with:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce, a proof of concept, or relevant code locations.
  • Affected version, operating system, and package type.
  • Any suggested mitigation, when available.

Do not include real household records, receipt images, access tokens, passwords, database files, or backup archives in a report.

Supported Versions

Security fixes are applied to the current development branch and the latest released version when a release exists.

Local Data

Ivenn stores inventory information and attachments locally. Contributors must preserve this expectation: do not add telemetry, cloud uploads, or third-party data transfers without explicit user consent, clear documentation, and maintainer approval.

There aren't any published security advisories