If you discover a security vulnerability in Spokes Server, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, email [email protected] with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and aim to release a patch within 7 days for critical vulnerabilities.
| Version | Supported |
|---|---|
| Latest | ✅ Full support |
| < Latest | Security patches only (tagged -security) |
We kindly ask that you:
- Allow us reasonable time to investigate and patch the vulnerability before public disclosure
- Avoid accessing or modifying other users' data
- Act in good faith to avoid privacy violations, destruction of data, and interruption of service
We will credit researchers who report valid vulnerabilities (unless they prefer to remain anonymous).