Skip to content

Security: mmycin/Rooftime-App

Security

docs/SECURITY.md

Security Policy

Supported Versions

We take security seriously in Rooftime. The following versions are currently supported with security updates:

Version Supported
1.x ✅ Yes (Latest)
0.x ❌ No (Upgrade Recommended)

Reporting a Vulnerability

If you discover a security vulnerability in Rooftime, please do not disclose it publicly. Instead, follow these steps:

  1. Email us at security@rooftime.vercel.app to report the vulnerability.
  2. Include a detailed description of the vulnerability, steps to reproduce, and potential impact.
  3. We will acknowledge your report within 48 hours and begin investigating.
  4. Once the issue is confirmed, we will work on a fix and notify you when the patch is released.
  5. Responsible disclosure is appreciated—do not exploit the vulnerability for malicious purposes.

Security Best Practices for Contributors

If you're contributing to the project, keep these security best practices in mind:

  • Use secure coding practices (e.g., validate inputs, escape outputs, avoid SQL/NoSQL injection).
  • Never commit sensitive data (e.g., API keys, database credentials, JWT secrets).
  • Follow dependency updates to avoid known security vulnerabilities.
  • Report suspicious activities in the repo.

Bug Bounty

While we don’t have a formal bug bounty program (yet!), we appreciate all security researchers who responsibly report vulnerabilities. If your report is valid and critical, we might offer you a cool shoutout and possibly some exclusive Rooftime swag! 🎉

Final Note

Security is a shared responsibility. If you see something, say something. Let’s keep Rooftime secure for everyone. 🔒🚀

There aren’t any published security advisories