LUP4LDN (Land Use Planning for Land Degradation Neutrality) is deployed and used by planning teams and institutional partners in several countries. We take reports of security issues seriously and appreciate responsible disclosure.
This policy applies to both LUP4LDN repositories:
LUP4LDN is actively maintained on the main branch of each repository, which
reflects the current production deployment at
landusetool.org. Security fixes are applied
to main and released promptly; there is no separate long-term-support
branch at this time.
Please do not open a public GitHub issue for a security vulnerability.
Instead, email lup4ldn@scio.systems with:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof of concept if available.
- The repository and version/commit affected.
- Your contact details, if you would like to be credited or kept updated.
You should expect an acknowledgement within 5 business days. We will work with you to understand and confirm the issue, keep you informed of progress toward a fix, and coordinate on disclosure timing — we ask that details are not made public until a fix has been released.
This policy covers the LUP4LDN backend API and frontend dashboard as published in the two repositories above. It does not cover third-party services LUP4LDN depends on (e.g. Trends.Earth, SoilGrids, AWS) — please report issues in those services to their respective maintainers.
We are grateful to everyone who helps keep LUP4LDN and its users safe.