Skip to content

Security: INDIGOAZUL/la-tanda-web

Security

SECURITY.md

Security Policy

Supported Versions

La Tanda is in active development. Security updates are applied to the latest release on the main branch. Older versions are not maintained.

Version Supported
Latest (main)
Older releases

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, email security@latanda.online with:

  • A description of the vulnerability and its impact
  • Steps to reproduce (a proof-of-concept if possible)
  • Any suggested remediation

Response Timeline

  • Acknowledgment: within 72 hours of your report
  • Status update: within 7 days, with an assessment and an expected fix timeline
  • Disclosure: coordinated with you once a fix is released

Scope

This policy covers the code in this repository. For issues affecting the live platform at latanda.online or the La Tanda Chain network, the same address (security@latanda.online) applies.

We appreciate responsible disclosure and will credit reporters who wish to be acknowledged.

There aren't any published security advisories