Skip to content

Security: erickdronski/mend-app

SECURITY.md

Security policy

Reporting a vulnerability

Please do not disclose vulnerabilities, private relationship data, crisis content, credentials, or reproduction details in a public issue.

Use GitHub's private vulnerability reporting flow. Include the affected component, impact, reproduction steps, and any suggested mitigation. You should receive an acknowledgement within five business days.

Supported version

Security fixes target the current main branch and the current TestFlight release candidate. Older builds are not independently supported.

Scope

Reports involving authentication, shared spaces, account deletion, device locking, local records, safety routing, Supabase policies, or release credentials are especially important.

There aren't any published security advisories