Skip to content

Security: nistrahq/demy-admins

Security

SECURITY.md

Security Policy

Available languages:

Supported Versions

This project is academic and private.
Security updates are applied only to the active development branch (develop) and the latest stable release (main).
Older versions or tags are not maintained.


Reporting a Vulnerability

Please do not disclose vulnerabilities publicly in Issues or Pull Requests.

Instead, report them privately to the maintainers:

  • Contact: demy@gmail.com
  • Or via the private channel indicated in our team’s Discord.

When reporting, please include:

  • A description of the issue and its potential impact.
  • Steps to reproduce the vulnerability (screenshots, reproduction steps, or test accounts).
  • Any logs, stacktraces, or crash reports (shared privately, never in public).
  • Suggested mitigation or fix (if known).

We will acknowledge receipt of your report within 48 hours and aim to provide an initial assessment within 5 working days.


Scope

This policy applies to:

  • The Android application codebase (Kotlin, Jetpack Compose, Room, etc.).
  • App configurations, Gradle scripts, and sensitive resources.
  • Authentication, storage, and data handling within the app.

This policy does not apply to:

  • External dependencies (report issues directly to their maintainers).
  • Local emulator/device issues unrelated to the app itself.
  • Academic or classroom-related feedback (should be handled via the course platform).

Responsible Disclosure

By following this policy, you help us address security issues responsibly.
We will credit contributors in internal documentation, but no public disclosure will be made without team agreement.

Note: This repository is an academic and private project. External contributions are not accepted.

There aren't any published security advisories