Skip to content

Security: crispilly/brassica

Security

SECURITY.md

Brassica – Security Policy

Thank you for helping to improve the security of this project.

Reporting Security Vulnerabilities

If you discover a potential security vulnerability in Brassica, please do not report it publicly (e.g. not as a GitHub issue or comment).

Instead, please contact us privately at:

Email:
mail@crispilly.de

What to Include in Your Report

  • a brief description of the vulnerability
  • steps to reproduce the issue (if possible)
  • potential impact
  • a way to contact you for follow-up questions

Response Time

I aim to respond within 48 hours and to work on a fix as quickly as possible.

Disclosure Policy

Please disclose details about security vulnerabilities only after:

  1. the issue has been analyzed
  2. a fix has been provided
  3. users have had sufficient time to update

This helps protect all users of the web app.

Scope

This policy applies to:

  • the Brassica web app
  • all PHP, JavaScript, ZIP, import, and export functionality
  • the SQLite database
  • API endpoints
  • the entire project codebase in this repository

There aren't any published security advisories