Skip to content

Security: muety/wakapi

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security issues seriously. We appreciate good-faith reports and will make every effort to review legitimate findings responsibly.

To report a security issue, please use the GitHub Security Advisory "Report a Vulnerability" tab or send an email to the core maintainer Ferdi.

For low-severity issues (use best judgmenet), simply open an issue via the issue tracker instead.

What to include

Please include detailed information on the issue and why it's a security vulnerability as well as step-by-step reproduction instructions. Include a realistic impact statement and, additionally, logs, screenshots, request exmaples or a proof of concept where applicable.

After the initial reply to your report, we may ask for additional information, reproduction steps, affected versions, configuration details, or proof-of-concept material needed to verify the issue.

AI-assisted submissions

If you use AI tools to help draft or investigate a report, please disclose this and verify the result yourself before submission. Submitting unverified AI-generated claims creates unnecessary review work and slows down handling of legitimate reports.

Please note that we will not give credits to the submitter of reports that are obviously purely or largely generated by AI or in an otherwise automated fashion.

This document was inspired by Paperless-ngx' SECURITY.md.

Learn more about advisories related to muety/wakapi in the GitHub Advisory Database