Skip to content

Security: king04aman/HabiTrack

Security

SECURITY.md

HabiTrack Security Policy

We take the security of HabiTrack very seriously. If you discover a vulnerability or have concerns about the security of any part of the project (backend, desktop, or mobile components), we appreciate your efforts to help us improve our security posture. This document outlines our process for receiving and responding to security reports.

Reporting a Vulnerability

Do not create public issues for security vulnerabilities. Instead, please report them privately by following the steps below:

  1. Email Us:
    Send an email with full details to our security team at:
    king04aman+github@gmail.com

  2. What to Include:

    • A clear and detailed description of the vulnerability.
    • Steps to reproduce the issue (if applicable).
    • The affected version(s) or components of HabiTrack.
    • Any relevant logs, screenshots, or files that can help us understand the problem.
    • Your contact information, so we can reach you for clarification if needed.

Our Commitment

  • Acknowledgment: We will acknowledge receipt of your report as soon as possible.
  • Response Time: Our goal is to respond to security reports within 3-5 business days.
  • Resolution: Once a vulnerability is confirmed, we will work to address and resolve the issue promptly. We kindly request that you give us time to fix the vulnerability before making any public disclosures.
  • Credit: If you wish to remain anonymous, please let us know. Otherwise, we may acknowledge your contribution in our release notes or security advisory.

Responsible Disclosure

We appreciate responsible disclosure. We ask that you:

  • Keep Details Confidential: Until we have had an opportunity to investigate and resolve the issue.
  • Coordinate with Us: Refrain from publicizing any details about the vulnerability until a fix has been deployed, to minimize risk to our users.

Legal Safe Harbor

If you are a security researcher acting in good faith and following this policy, we will not pursue legal action against you under the Computer Fraud and Abuse Act (CFAA) or any other applicable laws.

Thank You

Your help is vital to making HabiTrack secure. We appreciate your efforts in reporting vulnerabilities and assisting us in improving the project for everyone.

For any further questions or concerns regarding security, please contact us at: king04aman+github@gmail.com

There aren't any published security advisories