Skip to content

Security: SpaceEngineerSS/CosmoRisk

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.0.x
< 2.0

Reporting a Vulnerability

If you discover a security vulnerability in CosmoRisk, please report it responsibly.

How to Report

  1. DO NOT create a public GitHub issue for security vulnerabilities
  2. Send an email to: spacegumus@gmail.com
  3. Include the following information:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution: Depends on severity (critical: 24-48h, high: 7 days, medium: 30 days)

Disclosure Policy

  • We follow responsible disclosure practices
  • We will credit researchers who report valid vulnerabilities (unless anonymity is requested)
  • Please allow us reasonable time to fix the issue before public disclosure

Security Measures

This application:

  • Does not store NASA API keys on any server (local storage only)
  • Does not collect or transmit personal data
  • Uses HTTPS for all API communications
  • Runs in a sandboxed Tauri environment

Contact


Last updated: 18.12.2025

There aren’t any published security advisories