Skip to content

Security: GalaxyPay/lute

Security

SECURITY.md

Security Policy

This security policy applies to all Lute open-source components.

Supported Versions

Only the latest release of each component receives security updates.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, report vulnerabilities via email to security@lute.app with "SECURITY" in the subject line.

Please include the following in your report:

  • Description of the vulnerability
  • Affected component(s)
  • Steps to reproduce
  • Impact assessment (what an attacker could achieve)

We will acknowledge your report within 5 business days.

Response Process

  1. Acknowledgment — We confirm receipt of your report within 5 business days.
  2. Triage — We assess severity and determine affected components.
  3. Fix Development — We develop a patch and keep you informed of progress.
  4. Release — We publish the fix and a security advisory.
  5. Credit — We credit you in the advisory, unless you prefer to remain anonymous.

Coordinated Disclosure

We ask that you give us 90 days to address a reported vulnerability before any public disclosure.

  • We will keep you informed of our progress throughout the disclosure window.
  • If a fix is released before the 90-day window closes, both parties are free to disclose.
  • If we cannot meet the 90-day window, we will work with you to negotiate an extension.

Scope

In scope:

  • Security vulnerabilities in Lute code

Out of scope:

  • Vulnerabilities in third-party dependencies (please report these upstream)
  • Hosting services or infrastructure providers

Safe Harbor

We will not pursue legal action against security researchers who:

  • Act in good faith and follow this policy
  • Avoid privacy violations, data destruction, and service disruption
  • Report vulnerabilities through the process described above

We consider security research conducted under this policy to be authorized activity.

There aren’t any published security advisories