Skip to content

Security: Yaugourt/LiquidTerminal_Back

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do NOT open a public GitHub issue
  2. Send an email to security@liquidterminal.xyz with:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity
    • Critical: 24-48 hours
    • High: 1 week
    • Medium: 2 weeks
    • Low: Next release

Scope

  • Backend API (this repository)
  • Authentication and authorization
  • Data integrity and privacy
  • Rate limiting and denial of service

Out of Scope

  • Issues in third-party dependencies (report to the dependency maintainer)
  • Social engineering attacks
  • Denial of service via legitimate API usage within rate limits

Recognition

We appreciate responsible disclosure and will credit reporters (with permission) in our release notes.

There aren't any published security advisories