Skip to content

Security: jaherhum/crowdroom

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release of Crowdroom receives security updates. Older versions are not maintained.

Reporting a Vulnerability

If you find a security vulnerability, do not open a public issue.

Send an email to: crowdroom@jaherhum.dev

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Process

  1. You will receive a confirmation within 48 hours
  2. The issue will be investigated and a fix developed
  3. A new release will be published with the fix
  4. You will be credited in the changelog (unless you prefer anonymity)

Scope

In scope:

  • Authentication and authorization issues
  • Data exposure or privacy issues
  • WebSocket security issues
  • API vulnerabilities

Out of scope:

  • Denial of service attacks
  • Issues in third-party dependencies (report those upstream)
  • Social engineering

There aren't any published security advisories