The integrity of tree verification and the safety of supporter data are core to Vriksha.
Please do not open a public GitHub issue for security problems. Public disclosure could let bad actors exploit the issue β or game tree verification β before it's fixed.
Report privately via either:
- π GitHub private vulnerability reporting (preferred): repo Security tab β Report a vulnerability.
- π§ Email: ganeshbodke2@gmail.com
Please include what you found, steps to reproduce, and the potential impact.
- Exposed secrets or credentials
- Ways to access or leak supporter/donor personal data
- Ways to fake or game tree verification (e.g., registering trees that weren't planted, or marking dead trees as alive)
- Authentication/authorization flaws (relevant once the Supabase backend lands)
- Anything that could undermine trust in the platform's data
- We'll acknowledge your report as quickly as we can.
- We'll keep you updated as we investigate and fix.
- With your permission, we're happy to credit you once the issue is resolved.
Thank you for helping keep Vriksha trustworthy. π³