Skip to content

Security: Medal-Social/NextMedal

.github/SECURITY.md

Security Policy

Supported Versions

Currently, only the latest version of the main branch is supported for security updates.

Version Supported
Latest
< Latest

Reporting a Vulnerability

If you discover a security vulnerability within this project, please report it privately.

DO NOT create a public issue for security vulnerabilities.

Preferred Reporting Method

Please send an email to support@medalsocial.com or use GitHub's private vulnerability reporting feature if enabled for this repository.

What to include in your report

A good security report should include:

  1. Type of issue: (e.g., SQL injection, XSS, etc.)
  2. Location: The file and line number where the issue exists.
  3. Proof of Concept: Steps to reproduce the issue or a script that demonstrates it.
  4. Impact: How this issue could be exploited and what the consequences could be.

Our Response Process

  1. Acknowledgment: We will acknowledge your report within 48 hours.
  2. Verification: We will work to verify the vulnerability and assess its severity.
  3. Fix: We will develop a fix and test it.
  4. Disclosure: We will coordinate with you on the timing of a public disclosure, typically after a fix has been released.

Thank you for helping keep this project secure!

There aren't any published security advisories