Skip to content

Security: FoldedOdin/Japanese-flashcard-website-

Security

SECURITY.md

Security Policy

Supported Versions

We support the latest stable production release. Version pinning is recommended for consistency.

Version Supported
Main
Legacy

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability, please report it privately.

Please do not report security vulnerabilities via public GitHub issues.

How to Report

Please report vulnerabilities via GitHub Security Advisories or by contacting the repository owner. Include:

  1. Type of issue (e.g., SQL injection, XSS, RLS bypass).
  2. Steps to reproduce the issue.
  3. Potential impact of the vulnerability.
  4. (Optional) Suggested fix or mitigation.

Our Response Process

  1. We will acknowledge receipt of your report within 48 hours.
  2. We will provide an estimated timeline for a fix based on severity.
  3. We will notify you once the vulnerability is addressed.

Severity Levels

  • Critical: Immediate action (≤24h). Exploitable vulnerabilities with high data impact.
  • High: Fix within 3–5 days. Severe issues requiring specific conditions.
  • Medium: Fix within 1–2 weeks. General security improvements.
  • Low: Best effort. Minimal risk or hardening.

Scope

This policy applies to:

  • Web application (Frontend & Backend APIs)
  • Supabase Edge Functions
  • Database RLS policies

Safe Harbor

We will not take legal action against researchers who:

  • Act in good faith to protect users.
  • Do not exploit vulnerabilities beyond a Proof of Concept (PoC).
  • Follow this disclosure policy and provide reasonable time for remediation.

Responsible Disclosure

We ask that you follow responsible disclosure principles and allow us a reasonable amount of time to fix the issue before sharing any information publicly.

There aren't any published security advisories