Skip to content

Security: FragDB/fragrance-database

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest Yes

Reporting a Vulnerability

If you discover a security vulnerability in the FragDB sample data, code examples, or documentation, please report it responsibly.

How to Report

  1. Email: Send details to support@fragdb.net
  2. Subject: Include "SECURITY" in the subject line
  3. Details: Provide a clear description of the vulnerability

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 7 days
  • Resolution: Depending on severity, typically within 30 days

What We Will Do

  1. Acknowledge receipt of your report
  2. Investigate the issue
  3. Develop and test a fix
  4. Release the fix and credit you (if desired)

Scope

This security policy applies to:

  • Sample data files in this repository
  • Code examples in the examples/ directory
  • Documentation and markdown files

Out of Scope

  • The full FragDB database (report issues at fragdb.net)
  • Third-party dependencies
  • Issues in forked repositories

Data Privacy

The sample data contains only publicly available fragrance information. No personal data is included.

Contact

There aren't any published security advisories