Skip to content

Security: KanadeK/rosterfair

Security

SECURITY.md

Security policy

Supported versions

The latest GitHub Release receives security fixes.

Version Supported
0.1.x Yes
Older No

Report privately

Use GitHub private vulnerability reporting. Do not open a public issue for a vulnerability that could expose roster data, inject active content into reports, escape an output path, or bypass a hard constraint.

Include a minimal synthetic scenario, affected version, platform, command, observed result, and expected result. Do not include real names or sensitive attributes.

Data handling

RosterFair makes no network requests and has no telemetry. Inputs and outputs remain local. HTML reports embed the full assignment data so they work offline; anyone who receives the report can inspect that data.

The release preflight scans common secret formats, but it cannot prove that arbitrary names, notes, or custom attributes are safe to publish.

There aren't any published security advisories