Skip to content

Security: SafariDeskTicketing/safaridesk

Security

SECURITY.md

Security Policy

Please do not report security vulnerabilities through public issues.

For now, use the private security contact listed on the SafariDesk website or the official support channel for your SafariDesk deployment.

Before reporting, include:

  • SafariDesk version or Docker image tag.
  • Deployment type.
  • A concise vulnerability description.
  • Reproduction steps.
  • Logs or screenshots only after removing secrets.

Do not share .env, access tokens, license keys, SMTP credentials, OAuth secrets, database dumps, or uploaded customer data in public channels.

For deployment hardening, read the production deployment guide and configuration reference.

There aren't any published security advisories