Security fixes are applied to active development branches only:
maindevelopment
Older branches or tags may not receive security updates.
Please do not open a public GitHub issue for suspected security vulnerabilities.
Use one of the private channels below:
- Create a private security advisory in this repository (preferred).
- Contact a maintainer directly and include "Security" in the subject.
Private advisory link: https://github.com/code-the-dream-school/summer-26-js-practicum-team2/security/advisories/new
If a public issue is created accidentally, keep details minimal and move to a private advisory as soon as possible.
If you are unsure whether something is a vulnerability, report it anyway.
Please include as much of the following as possible:
- A clear description of the issue
- Steps to reproduce
- Affected area (
frontend,backend, or both) - Potential impact
- Any proof-of-concept details (screenshots, logs, payloads)
- Suggested fix, if you have one
- Initial acknowledgment: within 3 business days
- Triage decision: within 7 business days
- Fix timeline: depends on severity and complexity
We will keep reporters informed during triage and remediation.
Please wait for confirmation that a fix is available before public disclosure.
After remediation, we may publish a summary of the issue and resolution.