Skip to content

Security: Lintshiwe/V-CrisisLink

Security

SECURITY.md

πŸ›‘οΈ Security Policy

βœ… Supported Versions

Version Supported
5.1.x βœ…
5.0.x ❌
4.0.x βœ…
< 4.0 ❌

πŸ“£ Reporting a Vulnerability

If you discover a security issue, please follow these steps:

  1. Email: Send a detailed report to lintshiwe1452@gmail.com
  2. **
  3. Response Time: Expect acknowledgment within 48 hours.
  4. Disclosure Timeline: We aim to resolve and disclose responsibly within 14 days.

πŸ” Scope of Investigation

We welcome reports on:

  • Data exposure or leakage
  • Authentication bypass
  • Privilege escalation
  • API abuse or injection
  • Disaster alert spoofing or manipulation

🚫 Out of Scope

  • UI bugs without security impact
  • Rate limiting suggestions
  • Feature requests

πŸ§ͺ Validation & Patch Workflow

All accepted vulnerabilities will be:

  • Reproduced in a test environment
  • Patched in a dedicated branch
  • Merged after CI/CD validation
  • Documented in release notes

πŸ… Recognition

Valid reports may earn:

  • A GitHub badge on your profile
  • Contributor credit in the changelog
  • CrisisLink Hall of Fame mention

There aren’t any published security advisories