Skip to content

Security: IvGolovach/radish-core

SECURITY.md

Security Policy

Supported Versions

Security fixes are developed against the latest released minor version. Before the first public release, the main branch is the only supported version.

Report A Vulnerability

Use GitHub's private vulnerability reporting flow under Security → Advisories → Report a vulnerability. If that option is unavailable, email security@radish.money.

Do not open a public issue for a suspected vulnerability. Do not include real receipt images, personal grocery histories, production credentials, household sync secrets, or data belonging to another person.

A useful report contains:

  • the affected version or source commit;
  • the affected package and API;
  • reproduction steps or a minimal synthetic test case;
  • expected and observed behavior;
  • the potential confidentiality, integrity, or availability impact; and
  • any known prerequisites or mitigations.

We will confirm receipt as soon as practical, investigate privately, coordinate a fix and release when appropriate, and credit reporters who want attribution. Please allow time for remediation before public disclosure.

Scope

Reports are in scope when they affect sealed objects, bundle authentication, resource limits, correction or deletion semantics, migration safety, pairing payload validation, or an accidental disclosure in this repository.

Issues confined to the private Radish application, a processing provider, cloud transport configuration, or the App Store binary may still be reported through the same private channels, but they are outside the properties documented by Radish Core.

There aren't any published security advisories