Skip to content

Security: secwexen/aappmart

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in AAPP-MART, please report it responsibly.

Preferred method:

  • Open a private GitHub Security Advisory

Please do not disclose security issues publicly until a fix or mitigation has been released.


Response Expectations

  • Initial response: within 72 hours
  • Fix or mitigation: as soon as reasonably possible
  • Coordinated disclosure will be handled in collaboration with the reporter

Supported Versions

Security updates are provided only for the latest stable release of AAPP-MART.
Older versions may not receive security fixes.


Scope

This project does not provide exploit code.

Valid reports include:

  • Code-level security weaknesses
  • Dependency vulnerabilities
  • Logic flaws affecting security
  • Configuration or deployment misconfigurations

Out of scope:

  • Social engineering
  • Denial-of-service via unrealistic traffic
  • Issues requiring physical access

Credits

We appreciate responsible disclosure and will acknowledge reporters when appropriate.

There aren’t any published security advisories