Skip to content

Security: NikolayAir/Boardstep

SECURITY.md

Security Policy

Supported Versions

Security reports are considered for the latest published release and the current main branch.

Version or branch Supported
Latest release Yes
main Yes
Earlier releases No

Security fixes, when required and practical, will normally target the current main branch. A corresponding release may be published when appropriate.

Reporting a Vulnerability

Please do not report suspected security vulnerabilities through public issues, discussions, pull requests, or other public channels.

Use the repository's Security tab and select Report a vulnerability to submit a private report through GitHub Private Vulnerability Reporting.

A useful report should include, where applicable:

  • a concise description of the issue;
  • the affected release, commit, or deployed application state;
  • reproducible steps or a minimal proof of concept;
  • the potential security impact;
  • relevant browser, operating-system, Python, dependency, environment, or configuration details;
  • any known mitigation or suggested remediation.

Please avoid including unrelated personal, confidential, authentication, or other sensitive data.

What to Expect

Reports will be reviewed as availability permits. No fixed acknowledgement, response, or remediation timeline is guaranteed.

Additional information may be requested to reproduce and assess the issue. Confirmed vulnerabilities may be handled privately through a GitHub Security Advisory while remediation and coordinated disclosure are prepared.

Non-Security Reports

Ordinary defects, usability problems, documentation issues, and feature requests that do not expose sensitive information should be reported through the public issue tracker.

There aren't any published security advisories