Skip to content

Security: temakubik/ycode

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in Ycode, please report it responsibly.

Do not open a public issue. Instead, email us at:

info@ycode.com

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fixes (if applicable)

Response Timeline

  • Acknowledgement: Within 48 hours of your report
  • Initial assessment: Within 5 business days
  • Resolution: Depends on severity, but we aim to patch critical issues within 14 days

Disclosure Policy

We follow coordinated disclosure. We ask that you:

  1. Allow us reasonable time to investigate and fix the issue before public disclosure
  2. Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
  3. Do not access or modify other users' data

We will credit reporters in the release notes (unless you prefer to remain anonymous).

Scope

This policy applies to the Ycode application code in this repository. For issues related to third-party services (Supabase, Vercel), please report to those providers directly.

There aren’t any published security advisories