Skip to content

Security: UoMResearchIT/CapX

SECURITY.md

Security Policy

Reporting a Vulnerability

The CapX project takes security vulnerabilities seriously and appreciates responsible disclosure from the security community.

If you discover a security vulnerability in CapX, please report it using GitHub's Private Vulnerability Reporting feature rather than opening a public issue.

To submit a report:

  1. Navigate to the repository's Security tab.
  2. Select Report a vulnerability.
  3. Provide as much information as possible, including:
    • A description of the issue
    • Steps to reproduce
    • Potential impact
    • Any suggested mitigation or fix

Please do not disclose the vulnerability publicly until the issue has been investigated and a fix has been made available.

What to Expect

Maintainers will:

  • Acknowledge receipt of your report as soon as practical.
  • Review and validate the reported issue.
  • Work to understand the impact and determine an appropriate fix.
  • Keep you informed of significant progress where possible.
  • Credit you for the discovery if you wish to be acknowledged.

Scope

This policy applies to vulnerabilities in the CapX application and its official source code repository.

The following are generally considered out of scope:

  • Vulnerabilities in modified or self-hosted deployments caused by local configuration
  • Vulnerabilities that require physical access to infrastructure not controlled by the project
  • Issues arising solely from third-party dependencies where no CapX-specific weakness exists

Supported Versions

CapX is developed as an active open-source project. Security fixes will normally be applied to the current development version and then rolled out to production environments in the next release.

Responsible Disclosure

We ask security researchers to:

  • Avoid accessing, modifying, or deleting data belonging to others.
  • Avoid actions that could impact the availability of systems.
  • Provide sufficient detail to reproduce the issue.
  • Allow a reasonable period for investigation and remediation before any public disclosure.

Thank you for helping keep CapX and its users secure.

There aren't any published security advisories