Skip to content

Security: grandnode/grandnode2

SECURITY.md

Security Policy

Supported versions

Security fixes are made on the develop branch and shipped in the next release. We recommend running the latest stable release and upgrading when a new one is published.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions or pull requests.

Report them privately through GitHub's vulnerability reporting form. Include as much of the following as you can:

  • the type of issue (for example cross-site scripting, broken access control, injection),
  • the affected component and the files or URLs involved,
  • the GrandNode version or commit you tested,
  • step-by-step instructions or a proof of concept to reproduce it,
  • the impact, as you understand it.

We will acknowledge the report, keep you informed while we work on a fix, and credit you in the security advisory unless you prefer to stay anonymous.

There aren't any published security advisories