Skip to content

Security: wicm84266964/Buddy2api

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest release and the current main branch. Older releases are not maintained unless a fix is explicitly backported.

Reporting a Vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub's Report a vulnerability option in the Security tab so the report and follow-up remain private.

Include the affected version or commit, a minimal reproduction, the expected impact, and any suggested mitigation. Never attach Work Buddy or CodeBuddy credentials, access or refresh tokens, generated API keys, account databases, unredacted request logs, or personal information.

You should receive an initial acknowledgement within 7 days. A validated report will be assessed and fixed according to its impact and exploitability.

There aren't any published security advisories