Skip to content

Security: iuliandita/ditero

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Ditero, please report it privately. Do not open a public issue.

Preferred: GitHub Private Vulnerability Reporting

Use GitHub's built-in private vulnerability reporting to submit a report. This keeps the details confidential until a fix is available.

Alternative: Direct Contact

Reach out to @iuliandita via GitHub.

What to Expect

  • Acknowledgment within 48 hours
  • Status update within 7 days
  • Fix and disclosure coordinated with you before any public announcement

Scope

This policy covers the Ditero application code, container images, Helm chart, and Kubernetes manifests in this repository. It does not cover third-party services Ditero integrates with (identity providers, notification channels, or a user-supplied PostgreSQL instance).

Supported Versions

Only the latest release is supported with security fixes. Run the most recent version.

There aren't any published security advisories