Skip to content

Security: passionseed/web

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public GitHub issue for security reports.

Email hi@passionseed.org and cc me@tinywifi.cc (Product Security Engineer). Include:

  • A description of the issue and its potential impact
  • Steps to reproduce, or a proof of concept
  • Affected URLs, routes, or components if known

We aim to acknowledge within 48 hours and will keep you updated as we investigate and fix.

Scope

The live application at www.passionseed.org and everything in this repository, including the hackathon subsystem and API routes under app/api/.

Notes for researchers

  • No destructive testing, credential guessing, or load testing against the production site.
  • Don't access or modify other users' data. If a proof of concept requires data access, use accounts and data you created yourself.
  • We appreciate good-faith research and will credit reporters if they'd like (with permission).

There aren't any published security advisories