Skip to content

Security: Quad4-Software/Athenaeum

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest release on the default branch. Older releases may not receive patches.

Reporting a vulnerability

Do not open a public issue for security problems.

Report privately through one of:

  1. GitHub Security Advisories for this repository (Security tab -> Report a vulnerability)
  2. Email: ivan@quad4.io

Include enough detail to reproduce the issue: affected version or commit, configuration, steps, and impact. Screenshots or proof-of-concept scripts help when they are safe to share privately.

What to expect

  • Acknowledgement within a few business days
  • A fix or mitigation plan when the report is accepted
  • Coordinated disclosure after a release is available, unless you ask us not to credit you

Please give us reasonable time to ship a fix before any public discussion.

Scope

In scope: Athenaeum server, web UI, install and deploy scripts in this repository, and default configuration that can expose hosts or data.

Out of scope: third-party dependencies reported only against upstream, local misconfiguration, and denial-of-service from unbounded legitimate traffic unless there is a clear, fixable bug.

Safe harbor

Good-faith research that follows this policy and avoids privacy harm, data destruction, and service disruption is welcome. Do not access other users' data or keep copies of sensitive information beyond what is needed to demonstrate the issue.

There aren't any published security advisories