Skip to content

Security: enderdash-com/deploy

Security

SECURITY.md

Security reports

Open the affected repository's Security tab. If Report a vulnerability is available, use that private form. If it is unavailable, contact the maintainers through EnderDash Discord and ask for a private reporting channel. Do not include exploit details in a public issue or community message.

What to include

  • Affected project, version or commit, and deployment platform.
  • The impact and the permissions an attacker needs.
  • A minimal reproduction with synthetic data.
  • Suggested fixes or mitigations, if available.

Remove real credentials and personal data. Share proof of concept code only through the agreed private channel.

Version and disclosure information

Include the exact affected version and whether the problem also occurs on current development code. Maintainers assess the report and agree on a fix and disclosure plan with the reporter. This document does not promise a response deadline or support for a specific older release.

Ordinary defects and setup questions belong in the support guide.

There aren't any published security advisories