Skip to content

Security: karwalski/interplanet

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest (interplanet.live)
Older pinned releases

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Report privately by emailing security@interplanet.live. Include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof-of-concept (if safe to share)
  • Any suggested fix, if you have one

We aim to acknowledge all reports within 48 hours and will keep you informed of progress toward a fix.

Disclosure Policy

  • We will confirm receipt and assess severity within 48 hours
  • We aim to release a fix within 14 days for critical issues
  • We will credit reporters in the release notes unless you prefer to remain anonymous
  • We ask that you give us reasonable time to address the issue before any public disclosure

Scope

This policy covers:

  • The web application at interplanet.live
  • The planet-time.js JavaScript library and all language ports
  • The LTX SDK and all language ports
  • The REST API (api/time.php, api/ltx.php)

Out of scope: third-party dependencies, infrastructure not operated by this project.

There aren’t any published security advisories