We actively support the following versions with security updates:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
We take the security of the FVH Application Evaluator seriously. If you believe you've found a security vulnerability, please report it to us as described below.
Please do not report security vulnerabilities through public GitHub issues.
- Email: Send details to security@forumvirium.fi
- Expected Response: Within 48 hours
- Disclosure: Coordinated disclosure after fix
- Type of vulnerability
- Full paths of source file(s) affected
- Location of affected source code (tag/branch/commit)
- Step-by-step instructions to reproduce
- Proof-of-concept or exploit code (if possible)
- Impact of the vulnerability
- Confirmation of receipt within 48 hours
- Regular updates on progress
- Credit in security advisory (if desired)
- Coordinated disclosure timeline
- Keep dependencies up to date
- Use secrets management (never commit secrets)
- Enable 2FA on accounts
- Review security advisories
- Run
npm audit(frontend) andpip-audit(backend) before submitting PRs - Never commit secrets or credentials
- Use environment variables for configuration
- Follow secure coding guidelines
This project uses:
- Dependabot: Automated dependency updates
- CodeQL: Static application security testing (SAST)
- detect-secrets: Pre-commit secret scanning
- Dependency Review: PR-level vulnerability checks
Security advisories are published through:
- GitHub Security Advisories
- Project release notes