Please do NOT open a public GitHub issue for security vulnerabilities.
We take security issues seriously and appreciate your responsible disclosure.
Email: chaher.dridi@esprit.tn
Or use GitHub's private vulnerability reporting feature:
- Go to the Security tab of this repository
- Click Report a vulnerability
- Provide details about the vulnerability
When reporting a security issue, please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Impact assessment (what could an attacker do?)
- Affected versions (if known)
- Screenshots or logs (if applicable)
- Initial response: Within 48 hours
- Status updates: Every 7 days
- Resolution timeline: Depends on severity (critical issues prioritized)
- We will acknowledge your report within 48 hours
- Our team will investigate and validate the issue
- We will develop and test a fix
- Once resolved, we will notify you and publish a security advisory (if appropriate)
- Keep your dependencies up to date
- Use strong, unique passwords
- Enable two-factor authentication (2FA)
- Review and audit third-party integrations
Thank you for helping keep our project secure! 🛡️