Skip to content

Security: Kaydeewrld/Inventree-openSource

Security

SECURITY.md

πŸ”’ Security Policy

πŸ›‘οΈ Supported Versions

We actively maintain the latest version of this project. Security updates will be provided for:

Version Supported
Latest βœ… Yes
Older ❌ No

Please update to the latest release to receive security patches and improvements.


πŸ“£ Reporting a Vulnerability

We take security seriously. If you discover any security vulnerabilities, please follow the steps below:

  1. Do not open a public issue.
  2. Contact us privately to report the issue.
  3. Email us at: security@kaydeewrld.dev
  4. Include as much detail as possible:
    • Steps to reproduce
    • Affected components/files
    • Expected vs. actual behavior
    • Any proof-of-concept or screenshots

We aim to respond within 72 hours and will work with you to verify and address the issue promptly.


βœ… Our Commitment

  • All vulnerabilities will be assessed and resolved based on severity.
  • Contributors will be credited (unless anonymity is requested).
  • Coordinated disclosure is encouraged. We appreciate responsible reporting.

πŸ” Security Best Practices

We recommend users and contributors follow these general security guidelines:

  • Keep dependencies up to date.
  • Avoid hardcoding credentials in code or configuration files.
  • Use .env files for sensitive settings and never commit them to version control.
  • Regularly scan your environment using tools like Dependabot or cargo-audit (for Rust projects).
  • Always verify third-party libraries before use.

🀝 Acknowledgements

We thank the open-source security community for helping us build and maintain a secure project. If you'd like to support our efforts or contribute to security hardening, feel free to sponsor or open a private discussion.


πŸ“„ License

This document is distributed under the MIT License.

There aren’t any published security advisories