Skip to content

Security: SCiO-systems/landusetool-frontend

Security

SECURITY.md

Security Policy

LUP4LDN (Land Use Planning for Land Degradation Neutrality) is deployed and used by planning teams and institutional partners in several countries. We take reports of security issues seriously and appreciate responsible disclosure.

This policy applies to both LUP4LDN repositories:

Supported versions

LUP4LDN is actively maintained on the main branch of each repository, which reflects the current production deployment at landusetool.org. Security fixes are applied to main and released promptly; there is no separate long-term-support branch at this time.

Reporting a vulnerability

Please do not open a public GitHub issue for a security vulnerability.

Instead, email lup4ldn@scio.systems with:

  1. A description of the vulnerability and its potential impact.
  2. Steps to reproduce, or a proof of concept if available.
  3. The repository and version/commit affected.
  4. Your contact details, if you would like to be credited or kept updated.

You should expect an acknowledgement within 5 business days. We will work with you to understand and confirm the issue, keep you informed of progress toward a fix, and coordinate on disclosure timing — we ask that details are not made public until a fix has been released.

Scope

This policy covers the LUP4LDN backend API and frontend dashboard as published in the two repositories above. It does not cover third-party services LUP4LDN depends on (e.g. Trends.Earth, SoilGrids, AWS) — please report issues in those services to their respective maintainers.

Thanks

We are grateful to everyone who helps keep LUP4LDN and its users safe.

There aren't any published security advisories