Security Policy
Supported Scope
Security fixes are targeted to the default branch and latest documented architecture.
| Branch | Support Status |
|---|---|
main | Supported |
| Older branches | Best effort only |
Reporting a Vulnerability
Please report vulnerabilities privately.
Preferred path:
- Use GitHub Security Advisories for this repository.
- Include affected area, impact, and reproduction steps.
- Include any proof-of-concept details needed for triage.
If GitHub Security Advisories are unavailable, contact the advisory inbox at advisory@barateza.org.
If the issue requires data protection review or involves personal data handling, copy the DPO at dpo@barateza.org.
Do not create a public issue for a suspected vulnerability.
What to Include
- Type of issue (auth bypass, data exposure, injection, etc.)
- Affected component and file paths
- Preconditions and attacker model
- Steps to reproduce
- Expected impact and severity estimate
- Suggested remediation if available
Response Targets
- Initial acknowledgment: within 3 business days
- Triage decision: within 7 business days
- Remediation plan or mitigation guidance: as soon as validated
These targets are goals and may vary based on complexity.
Disclosure Guidance
- Do not publicly disclose details until maintainers confirm remediation or mitigation.
- Public issues for security defects may be closed and redirected to private channels.
Security Baseline
Contributors should preserve these repository security constraints:
- Least privilege role enforcement
- Session expiration and re-authentication gating for protected actions
- Offline-safe behavior without protected submission after expiry
- Immutable audit history for attendance and student events
- Deletion justification for student removal
- LGPD-aligned handling of personal data