Skip to content

Security: GeotrekCE/Geotrek-rando-widget

.github/SECURITY.md

Security Policy

Supported Versions

Only the latest release of Geotrek-rando-widget is actively maintained and supported with security updates.

Version Supported
Latest ✅
Older ❌

Reporting a Vulnerability

We take the security of this project seriously. If you have discovered a security vulnerability, please do not open a public issue or discussion.

Instead, please submit your report privately using GitHub's Private Vulnerability Reporting:

  1. Navigate to the Security Advisories tab of this repository.
  2. Click on "Report a vulnerability" to start a private advisory draft.
  3. Provide as much detail as possible to help us understand and resolve the issue:
    • A clear description of the vulnerability and its potential impact.
    • Step-by-step instructions, code snippets, or a Proof of Concept (PoC) to reproduce the issue.
    • Any relevant details regarding the environment, browser, or configuration.

What to Expect

  • Acknowledgment: We aim to review and acknowledge receipt of your report as soon as possible.
  • Investigation & Fix: We will collaborate with you within the private advisory to investigate, reproduce, and patch the vulnerability.
  • Resolution: Once a fix is released, it will be documented in the release notes, and you will receive credit for the report (unless you prefer to remain anonymous).

There aren't any published security advisories