Skip to content

Security: kta1kri/chirpstack

Security

SECURITY.md

Security Disclosure Policy

Supported Versions

Only the latest version of ChirpStack is supported. Users are encouraged to upgrade to the latest version.

Reporting a Vulnerability

We take the security of this project seriously. If you believe you have found a security vulnerability, please report it to us responsibly.

Contact: info@brocaar.com

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

What to Include

When reporting, please include as much of the following as possible:

  • The type of issue
  • The location of the affected source code
  • Step-by-step instructions or a proof-of-concept to reproduce the issue
  • The potential impact, including how an attacker might exploit it

Our Commitment

  • We will acknowledge your report
  • We will keep you informed of our progress toward a fix
  • We will credit you in the release notes (unless you prefer to remain anonymous)
  • We ask that you give us a reasonable amount of time (typically 90 days) to address the issue before any public disclosure

Scope

This policy covers the code in this repository only. Vulnerabilities in third-party dependencies should be reported to their respective maintainers.

There aren't any published security advisories