Skip to content

Latest commit

 

History

History
24 lines (14 loc) · 1.46 KB

File metadata and controls

24 lines (14 loc) · 1.46 KB

Security Policy

Reporting a Vulnerability

If you believe you’ve identified a security vulnerability in Vernissage Server (for example, a flaw that could allow unauthorized access to data, bypass security checks, or perform actions that should not be possible), you can either:

A security issue is a problem in the software that could be exploited to harm users, compromise their privacy, or affect the integrity of the system.

You should not report such issues on public GitHub issues or in other public spaces. This gives us time to investigate and release a fix before the details become widely known, reducing the risk to Vernissage’s users.

Scope

A "vulnerability in Vernissage" refers to a flaw in the code provided through our official GitHub source code repository. Issues that arise from a specific deployment or configuration (for example, server misconfiguration or insecure hosting environment) are not considered vulnerabilities in Vernissage itself and should be reported directly to the administrator or owner of that particular installation, rather than to us.

Supported Versions

Below is the list of Vernissage Server (API) versions that receive security patches.

Version Supported
1.x.x