Skip to content

Security: ESA-Blueshell/website

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security issues in Blueshell seriously. If you discover a vulnerability, please report it responsibly rather than disclosing it publicly.

How to Report

Please email security concerns to: board@blueshell.utwente.nl

In your report, please include:

  • A description of the vulnerability
  • Steps to reproduce (if applicable)
  • Potential impact
  • Any suggested fix (optional)

Response Timeline

We will acknowledge your report within 2 business days and aim to provide an initial assessment within 1 week.

Supported Versions

Security updates will be provided for:

  • The current version on the main branch
  • Previous stable releases where practical

Disclosure Expectations

  • We request that you do not publicly disclose the vulnerability until we have had reasonable time to develop and release a fix
  • Typically, we aim to release security fixes within 2-4 weeks of notification
  • We will provide you with a timeline and may work with you on coordinating responsible disclosure

Security Considerations

See our README.md for an overview of our security measures, including:

  • JWT authentication
  • SQL injection prevention
  • XSS protection
  • CORS restrictions
  • TLS encryption

There aren't any published security advisories