Skip to content

Security: grimmory-tools/grimmory

SECURITY.md

Security Policy

How to Report

You can report security vulnerabilities through two channels:

  1. GitHub Security Advisory:

    • Navigate to the Security tab in our repository
    • Click on "Report a vulnerability"
    • Provide a detailed description of the vulnerability
  2. Direct contact:

    • Send your report to anybody with "maintainer" role discord
    • Please include as much information as possible about the vulnerability

What to Include

When reporting a vulnerability, please provide:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Any potential impact
  • If possible, suggestions for addressing the vulnerability
  • Your contact information for follow-up questions

Process

  1. Submit your report through one of the channels above
  2. Receive an acknowledgment
  3. We will investigate and validate the issue
  4. We will work on a fix and keep you updated on our progress
  5. Once resolved, we will publish the fix and acknowledge your contribution (if requested)

Supported Versions

Only the latest version of Grimmory is supported for security updates. We do not backport security fixes to older versions.

Version Supported
Latest
Older

Please note: Before reporting a security issue, ensure you are using the latest version of Grimmory. Security reports for older versions will not be accepted.

Security Best Practices

When deploying Grimmory:

  1. Always use the latest version
  2. Use strong, unique passwords for admin accounts
  3. Decrease permissions for any external services or integrations
  4. Run Grimmory in a secure environment (e.g., behind a firewall, with proper network segmentation)
  5. Regularly check for and apply updates

Note

this list is not exhaustive. Always follow general security best practices when deploying any software.

There aren’t any published security advisories