Skip to content

Security: voiceyBill/voiceyBill-web

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest default branch is supported for security updates.

Reporting a Vulnerability

Do not open public issues for security vulnerabilities.

Please use GitHub Security Advisories to privately disclose vulnerabilities. If advisories are not available, contact the maintainers through a private channel and include:

  • A clear description of the issue
  • Impact and affected components
  • Reproduction steps or proof of concept
  • Suggested remediation if available

Disclosure Process

  1. We acknowledge reports within 3 business days.
  2. We triage and confirm severity.
  3. We prepare and test a fix.
  4. We publish a coordinated disclosure with remediation guidance.

Scope

Security reports should focus on exploitable vulnerabilities, including but not limited to authentication bypass, data exposure, injection flaws, privilege escalation, and insecure dependency usage.

There aren't any published security advisories