Skip to content

Security: R3ACTR/NoteNest-Collaborative-Knowledge-Base

Security

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
main
older releases

Reporting a Vulnerability

If you discover a security vulnerability in this project, please do NOT open a public GitHub issue.

Instead, report it responsibly by emailing:

osq@r3actr.work

When reporting, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact (if known)
  • Any relevant screenshots, logs, or proof-of-concept code

Response Process

  • Security reports will be acknowledged within 48 hours
  • The maintainers will investigate and assess the issue
  • If confirmed, an appropriate fix or mitigation will be planned
  • Responsible disclosure will be followed before any public announcement

We appreciate responsible reporting and efforts to improve the security of this project.


Security Best Practices for Contributors

Contributors are encouraged to:

  • Avoid committing secrets (API keys, tokens, passwords)
  • Use environment variables and .env.example
  • Follow secure coding practices
  • Validate and sanitize user inputs
  • Report potential vulnerabilities responsibly

Scope

This security policy applies to:

  • Source code
  • Dependencies
  • Configuration files
  • Deployment-related files

Issues caused by outdated local environments or unsupported forks are out of scope.


Acknowledgements

We thank the community and contributors for helping keep this project secure.

There aren’t any published security advisories