The CapX project takes security vulnerabilities seriously and appreciates responsible disclosure from the security community.
If you discover a security vulnerability in CapX, please report it using GitHub's Private Vulnerability Reporting feature rather than opening a public issue.
To submit a report:
- Navigate to the repository's Security tab.
- Select Report a vulnerability.
- Provide as much information as possible, including:
- A description of the issue
- Steps to reproduce
- Potential impact
- Any suggested mitigation or fix
Please do not disclose the vulnerability publicly until the issue has been investigated and a fix has been made available.
Maintainers will:
- Acknowledge receipt of your report as soon as practical.
- Review and validate the reported issue.
- Work to understand the impact and determine an appropriate fix.
- Keep you informed of significant progress where possible.
- Credit you for the discovery if you wish to be acknowledged.
This policy applies to vulnerabilities in the CapX application and its official source code repository.
The following are generally considered out of scope:
- Vulnerabilities in modified or self-hosted deployments caused by local configuration
- Vulnerabilities that require physical access to infrastructure not controlled by the project
- Issues arising solely from third-party dependencies where no CapX-specific weakness exists
CapX is developed as an active open-source project. Security fixes will normally be applied to the current development version and then rolled out to production environments in the next release.
We ask security researchers to:
- Avoid accessing, modifying, or deleting data belonging to others.
- Avoid actions that could impact the availability of systems.
- Provide sufficient detail to reproduce the issue.
- Allow a reasonable period for investigation and remediation before any public disclosure.
Thank you for helping keep CapX and its users secure.