Currently supported versions with security updates:
| Version | Supported |
|---|---|
| 0.0.x | β |
We take security vulnerabilities seriously. If you discover a security issue, please follow these steps:
Please do not disclose security vulnerabilities publicly until they have been addressed.
Send a detailed report to the repository maintainers through:
- GitHub Security Advisories (preferred)
- Direct message to repository owner
- Email: [Add security contact email]
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if available)
- Your contact information
- Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours
- Investigation: We will investigate and validate the vulnerability
- Communication: We will keep you informed of progress
- Resolution: We will work on a fix and coordinate disclosure
- Credit: You will be credited for the discovery (if desired)
- Never commit
.envfiles or credentials - Use environment variables for sensitive data
- Keep dependencies up to date
- Follow secure coding practices
- Review code for security issues before submitting PRs
- Always use strong, unique passwords
- Keep your JWT secret secure
- Regularly update dependencies
- Use HTTPS in production
- Enable CORS properly
- Implement rate limiting
- Use prepared statements for database queries
- Validate and sanitize all user inputs
- JWT tokens expire after 24 hours
- Passwords hashed with bcrypt (10 salt rounds)
- MongoDB injection protection via Mongoose
- CORS configuration for allowed origins
-
Environment Variables
- Use strong JWT secrets (minimum 32 characters)
- Rotate secrets regularly
- Use environment-specific secrets
-
Database Security
- Use MongoDB Atlas with IP whitelist
- Enable authentication
- Use connection string with SSL
-
API Security
- Implement rate limiting
- Add helmet.js for security headers
- Use HTTPS only
- Implement request validation
- Add API authentication for all endpoints
-
Password Policy
- Enforce strong password requirements
- Implement password reset functionality
- Consider adding 2FA
-
Monitoring
- Log security events
- Monitor for suspicious activity
- Set up alerts for security issues
Security updates will be released as soon as possible after a vulnerability is confirmed. Updates will be announced through:
- GitHub Releases
- Security Advisories
- Repository README
We follow responsible disclosure practices:
- Vulnerabilities will be fixed before public disclosure
- Security advisories will be published after fixes are deployed
- Credits will be given to reporters (with permission)
Thank you for helping keep Vidya Setu secure! π