Skip to content

Security: APESCIC/MyAPES-Account

SECURITY.md

Security policy

Reporting a vulnerability

If you believe you have found a security vulnerability in MyAPES Core (APESCIC/MyAPES-Account), report it privately so repository administrators can review it before any public disclosure.

Use GitHub private vulnerability reporting:

Report a vulnerability

That form creates a private security advisory visible only to repository administrators. You can also open Security → Advisories → Report a vulnerability on this repository.

Do not open a public GitHub issue, discussion, or pull request for a suspected vulnerability. Do not describe suspected vulnerabilities in the public Change Log Hub or in public release notes.

This repository does not publish a separate security-contact email. GitHub private vulnerability reporting is the supported path to repository administrators.

What to include

Please include:

  • A short description of the issue and its impact
  • Steps to reproduce, or a proof of concept, if you have one
  • Affected versions or environments, if known
  • Any suggested mitigation

Do not include credentials, personal data, or production secrets in the report.

Supported versions

Security reports are accepted for the current released MyAPES Core version on main (see VERSION). Older beta versions may not receive a separate patch.

Public issues and change log

Use public issues only for non-security bugs and feature requests. The Change Log Hub records released, public-safe changes. It is not a channel for vulnerability reports.

There aren't any published security advisories