We support the latest stable production release. Version pinning is recommended for consistency.
| Version | Supported |
|---|---|
| Main | ✅ |
| Legacy | ❌ |
We take security seriously. If you discover a vulnerability, please report it privately.
Please do not report security vulnerabilities via public GitHub issues.
Please report vulnerabilities via GitHub Security Advisories or by contacting the repository owner. Include:
- Type of issue (e.g., SQL injection, XSS, RLS bypass).
- Steps to reproduce the issue.
- Potential impact of the vulnerability.
- (Optional) Suggested fix or mitigation.
- We will acknowledge receipt of your report within 48 hours.
- We will provide an estimated timeline for a fix based on severity.
- We will notify you once the vulnerability is addressed.
- Critical: Immediate action (≤24h). Exploitable vulnerabilities with high data impact.
- High: Fix within 3–5 days. Severe issues requiring specific conditions.
- Medium: Fix within 1–2 weeks. General security improvements.
- Low: Best effort. Minimal risk or hardening.
This policy applies to:
- Web application (Frontend & Backend APIs)
- Supabase Edge Functions
- Database RLS policies
We will not take legal action against researchers who:
- Act in good faith to protect users.
- Do not exploit vulnerabilities beyond a Proof of Concept (PoC).
- Follow this disclosure policy and provide reasonable time for remediation.
We ask that you follow responsible disclosure principles and allow us a reasonable amount of time to fix the issue before sharing any information publicly.