If you discover a security vulnerability in Ditero, please report it privately. Do not open a public issue.
Use GitHub's built-in private vulnerability reporting to submit a report. This keeps the details confidential until a fix is available.
Reach out to @iuliandita via GitHub.
- Acknowledgment within 48 hours
- Status update within 7 days
- Fix and disclosure coordinated with you before any public announcement
This policy covers the Ditero application code, container images, Helm chart, and Kubernetes manifests in this repository. It does not cover third-party services Ditero integrates with (identity providers, notification channels, or a user-supplied PostgreSQL instance).
Only the latest release is supported with security fixes. Run the most recent version.