Skip to content

Latest commit

 

History

History
44 lines (30 loc) · 1.32 KB

File metadata and controls

44 lines (30 loc) · 1.32 KB

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please do not open a public GitHub issue. Instead, report it privately to the team:

Email: info@hasadna.org.il

Please include:

  • A description of the vulnerability
  • Steps to reproduce it (if applicable)
  • The potential impact
  • Any known mitigations

Response Timeline

As a small volunteer project, we aim to:

  • Acknowledge receipt within 2 business days
  • Provide an initial assessment within 1 week
  • Release a fix or public mitigation within 2 weeks (depending on severity)

For critical vulnerabilities affecting deployed systems, we'll prioritize faster response.

In Scope

Security issues we're interested in:

  • Authentication or authorization flaws
  • Data exposure or leakage
  • API vulnerabilities
  • Dependency vulnerabilities (outdated packages with known CVEs)
  • Infrastructure misconfigurations

Out of Scope

  • Social engineering or phishing
  • Denial of service attacks
  • Vulnerabilities in third-party services or dependencies without a known fix
  • Issues requiring physical access or local credentials

Public Disclosure

Once a fix is released, we'll credit the researcher in the release notes (unless you prefer anonymity).

Thank you for helping keep this project secure.