Skip to content

Security: zite/applicant-tracking

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue for a security problem.

Report it privately through GitHub's advisory form, or email security@zite.com. We will acknowledge within three working days and keep you updated until it is resolved. If you would like credit in the advisory, say so and we will include you.

Scope

This repository is a template. It is installed into a workspace that you run, so a report against it is about the application code here: endpoint authorization, data exposure between people or organizations, injection through user-supplied content, that kind of thing.

Vulnerabilities in the Zite platform itself (auth, the endpoint runtime, hosting) go to security@zite.com too, but say which you mean.

What we already know and treat as by design

  • The demo data is public sample content: a fictional company, its jobs and candidates.
  • The careers site is an external app. Job posts and the application form are deliberately public; everything recruiter-facing lives in the internal app.
  • Candidate resumes are stored as Zite attachments. Their URLs are unguessable but not access-controlled, so treat them as secret links.

Supported versions

This is a template rather than a released library. Fixes land on main and you pick them up by merging. There are no maintained release branches.

There aren't any published security advisories