Skip to content

Security: benjosua/backspin

Security

SECURITY.md

Security Policy

Supported Versions

We actively provide security patches for the latest version on the main branch.

Version Supported
main
< 1.0

Reporting a Vulnerability

We take the security of Backspin seriously. If you believe you have discovered a security vulnerability in this project, please report it responsibly:

  1. Do NOT open a public GitHub issue describing the vulnerability.
  2. Use GitHub's private vulnerability reporting feature on this repository (under Security > Advisories > Report a vulnerability), or email the maintainer directly.
  3. Include detailed steps to reproduce the vulnerability, including:
    • A clear description of the potential impact.
    • Proof-of-concept (PoC) scripts, network traces, or payloads if available.
    • Affected components (Client, Server room logic, Auth, Database queries).

Response Timeline

  • Initial acknowledgment: Within 48 hours.
  • Assessment & Triage: Within 5 business days.
  • Fix & Disclosure: We will coordinate a fix and release an advisory once patched.

There aren't any published security advisories