Skip to content

Security: marassteiner/app

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security issues privately. Do not open a public issue.

Email: security@21.gifts

Include:

  • Description of the issue and its impact
  • Steps to reproduce
  • Affected versions or commit
  • Suggested fix, if any

You will receive an acknowledgement within a few days. Once the issue is verified, we will work on a fix and coordinate disclosure with you.

Scope

In scope:

  • This web frontend (app) and any subdomain it serves
  • The backend service at 21gifts/api

Out of scope:

  • Third-party NOSTR relays
  • Third-party wallets / address providers
  • Browser / OS / Passkey-authenticator vulnerabilities (please report to the respective vendor)

Hall of fame

Coming soon.

There aren't any published security advisories