Skip to content

Security: GannuRocks/vriksha

Security

SECURITY.md

Security Policy

The integrity of tree verification and the safety of supporter data are core to Vriksha.

Reporting a vulnerability

Please do not open a public GitHub issue for security problems. Public disclosure could let bad actors exploit the issue β€” or game tree verification β€” before it's fixed.

Report privately via either:

  • πŸ”’ GitHub private vulnerability reporting (preferred): repo Security tab β†’ Report a vulnerability.
  • πŸ“§ Email: ganeshbodke2@gmail.com

Please include what you found, steps to reproduce, and the potential impact.

What counts as a security issue

  • Exposed secrets or credentials
  • Ways to access or leak supporter/donor personal data
  • Ways to fake or game tree verification (e.g., registering trees that weren't planted, or marking dead trees as alive)
  • Authentication/authorization flaws (relevant once the Supabase backend lands)
  • Anything that could undermine trust in the platform's data

Our commitment

  • We'll acknowledge your report as quickly as we can.
  • We'll keep you updated as we investigate and fix.
  • With your permission, we're happy to credit you once the issue is resolved.

Thank you for helping keep Vriksha trustworthy. 🌳

There aren't any published security advisories