Skip to content

Security: myastroboard/.github

Security

SECURITY.md

Security Policy

This policy applies across the MyAstroBoard organization and all of its repositories. We take the security of the project and of the people who self-host it seriously, and we appreciate responsible disclosure.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report privately using GitHub's private vulnerability reporting:

  1. Go to the affected repository's Security tab.
  2. Click Report a vulnerability.
  3. Fill in the details.

This keeps the report confidential while we investigate. If private reporting is unavailable on a given repository, contact a maintainer privately rather than disclosing the issue publicly.

What to include

To help us assess and fix the issue quickly, please provide as much as you can:

  • A description of the vulnerability and its potential impact
  • The affected project and version (release tag or commit)
  • Step-by-step instructions to reproduce it
  • Any relevant configuration, logs, or proof-of-concept
  • Whether the issue is already publicly known

What to expect

  • We will acknowledge your report within a few days.
  • We will keep you updated on our assessment and progress.
  • We will work on a fix and coordinate a disclosure timeline with you.
  • With your permission, we're happy to credit you once the issue is resolved.

We ask that you give us a reasonable amount of time to address the issue before any public disclosure.

Supported versions

Security fixes are applied to the latest released version of each project. We strongly recommend keeping your deployment up to date with the most recent release. Older versions are not maintained.

Scope and self-hosting

MyAstroBoard projects are typically self-hosted. While we work to keep the software itself secure, the security of a deployment also depends on how it is operated — keep your instance updated, restrict network exposure as appropriate, and follow the deployment guidance in each repository's documentation.

Safe harbor

We support good-faith security research. If you make a genuine effort to follow this policy when reporting an issue, we will not pursue or support action against you for that research.

Thank you for helping keep MyAstroBoard and its community safe. 🌌

There aren't any published security advisories