Skip to content

Security: giauphan/codeatlas-platform

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.x ✅ Active development

Reporting a Vulnerability

We take the security of CodeAtlas AI seriously. If you believe you have found a security vulnerability, please report it to us as described below.

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via email to giauphan012@gmail.com (or open a private security advisory).

You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

Please include the following information:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Preferred Languages

We prefer all communications to be in English.

Policy

  • We will acknowledge receipt of your vulnerability report within 48 hours
  • We will send you a response indicating the next steps in handling your report
  • We will keep you informed of the progress towards a fix
  • We will notify you when the vulnerability is fixed

Scope

The following are considered out of scope:

  • Missing HTTP security headers (unless you can demonstrate a concrete exploit)
  • Rate limiting issues on non-authenticated endpoints
  • Self-XSS without a clear attack vector
  • Social engineering attacks against our team
  • Physical attacks against our infrastructure

Disclosure

We request that you do not publicly disclose the vulnerability until we have had the opportunity to address it. We will coordinate the disclosure timeline with you.

Recognition

We thank and recognize security researchers who help keep our community safe. With your permission, we will add your name to our acknowledgments.

There aren't any published security advisories