Skip to content

Security Policy

Supported Scope

Security fixes are targeted to the default branch and latest documented architecture.

BranchSupport Status
mainSupported
Older branchesBest effort only

Reporting a Vulnerability

Please report vulnerabilities privately.

Preferred path:

  1. Use GitHub Security Advisories for this repository.
  2. Include affected area, impact, and reproduction steps.
  3. Include any proof-of-concept details needed for triage.

If GitHub Security Advisories are unavailable, contact the advisory inbox at advisory@barateza.org.

If the issue requires data protection review or involves personal data handling, copy the DPO at dpo@barateza.org.

Do not create a public issue for a suspected vulnerability.

What to Include

  • Type of issue (auth bypass, data exposure, injection, etc.)
  • Affected component and file paths
  • Preconditions and attacker model
  • Steps to reproduce
  • Expected impact and severity estimate
  • Suggested remediation if available

Response Targets

  • Initial acknowledgment: within 3 business days
  • Triage decision: within 7 business days
  • Remediation plan or mitigation guidance: as soon as validated

These targets are goals and may vary based on complexity.

Disclosure Guidance

  • Do not publicly disclose details until maintainers confirm remediation or mitigation.
  • Public issues for security defects may be closed and redirected to private channels.

Security Baseline

Contributors should preserve these repository security constraints:

  • Least privilege role enforcement
  • Session expiration and re-authentication gating for protected actions
  • Offline-safe behavior without protected submission after expiry
  • Immutable audit history for attendance and student events
  • Deletion justification for student removal
  • LGPD-aligned handling of personal data

Distribuído sob licença MIT.