Skip to content

Security: nathanpond/n8Tracks

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue for a security problem. A public reproduction is a working exploit handed to everyone running n8Tracks.

Report privately through GitHub's private vulnerability reporting:

  1. Go to the repository's Security tab.
  2. Choose Report a vulnerability.
  3. Describe the problem, the affected version or commit, and how to reproduce it.

What to expect

n8Tracks is maintained by one person in their spare time. Reports are read and answered on a best-effort basis; there is no guaranteed response or fix timeline. You will be credited in the published advisory unless you ask not to be.

How findings are tracked

Security findings, whether reported externally or found by the project's own audits, are tracked as draft GitHub security advisories. They are visible only to maintainers until a fix is available, and are then published.

Supported versions

The project is pre-release. Only the latest commit on main is supported.

There aren't any published security advisories