Skip to content

Security: tnaydnov/eventa

Security

.github/SECURITY.md

Security Policy

About this repository

This is an archived personal project, published for reading only. Its production deployment has been shut down, and no licence to use the software is granted to anyone (see LICENSE).

There is therefore no live system to attack and no user data at risk. The code is not maintained and there is no patch pipeline.

Reporting a problem

If you spot a security flaw in the code while reading it, you are welcome to report it privately through GitHub Security Advisories rather than opening a public issue. It will be read with interest, but please note that no fix, response time or advisory is promised.

Helpful reports include:

  • what the flaw is and where it lives (file, route or endpoint),
  • how it would be exploited,
  • the impact you believe it has.

Please do not

  • Report vulnerabilities in third-party services (Supabase, SMS or payment providers) here — report those to the vendor.
  • Report findings that only apply to a deployment someone else stood up. Running this software is not permitted, and any such deployment is that operator's sole responsibility.

No liability

This software is provided "as is", with no warranty and no liability of any kind. See LICENSE and the Licence, disclaimer & liability section of the README.

There aren't any published security advisories