| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public GitHub issue
- Email security concerns to the maintainers
- Include a description of the vulnerability and steps to reproduce
- Allow reasonable time for a fix before public disclosure
This project implements:
- Row-Level Security (RLS) for multi-tenant data isolation
- HMAC-signed CSRF tokens
- Rate limiting on authentication endpoints
- Input validation via TypeBox schemas
- HttpOnly secure session cookies
- Automated dependency scanning via Dependabot
- Container image scanning via Trivy