If you discover a security vulnerability in deveconomics-toolkit, please report it responsibly.
Email: hello@impactmojo.in
Please do NOT open a public issue for security vulnerabilities.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgement: Within 48 hours
- Assessment: Within 5 business days
- Resolution: Within 7 days for critical issues
The following are in scope:
- XSS vulnerabilities in Shiny apps
- Data injection through user inputs
- Dependency vulnerabilities in R or Python packages
- Information disclosure
- DDoS attacks
- Social engineering
- Vulnerabilities in Shiny Server or hosting platforms