If you discover a security vulnerability in this project, please do not open a public GitHub issue. Instead, report it privately to the team:
Email: info@hasadna.org.il
Please include:
- A description of the vulnerability
- Steps to reproduce it (if applicable)
- The potential impact
- Any known mitigations
As a small volunteer project, we aim to:
- Acknowledge receipt within 2 business days
- Provide an initial assessment within 1 week
- Release a fix or public mitigation within 2 weeks (depending on severity)
For critical vulnerabilities affecting deployed systems, we'll prioritize faster response.
Security issues we're interested in:
- Authentication or authorization flaws
- Data exposure or leakage
- API vulnerabilities
- Dependency vulnerabilities (outdated packages with known CVEs)
- Infrastructure misconfigurations
- Social engineering or phishing
- Denial of service attacks
- Vulnerabilities in third-party services or dependencies without a known fix
- Issues requiring physical access or local credentials
Once a fix is released, we'll credit the researcher in the release notes (unless you prefer anonymity).
Thank you for helping keep this project secure.