We take the security and integrity of Smart Bhojan seriously. Because this application relies heavily on user input parsing via Streamlit and file compilation via ReportLab PDF libraries, we want to proactively prevent risks like cross-site scripting (XSS), dependency vulnerabilities, or HTML injection flaws.
Only the latest version running on the primary production branch receives security updates.
| Version | Supported |
|---|---|
| Main | ✅ Yes |
| < 1.0.0 | ❌ No |
Please do not open public GitHub issues for security vulnerabilities.
If you discover a security flaw or vulnerability within this application, follow these reporting steps:
- Draft a private message outlining the vulnerability.
- Include a clear description of the issue, step-by-step instructions to reproduce it, and any proof-of-concept scripts or screenshots.
- Send your report directly to the repository maintainer via their designated contact method or utilize GitHub's Private Vulnerability Reporting system if enabled on this fork.
- Acknowledgment: You will receive an acknowledgment of your report within 48 hours.
- Triage & Fix: We aim to investigate and address confirmed vulnerabilities within 7 to 14 days.
- Disclosure: Once a fix is pushed to the repository, proper attribution will be provided to the finder in the release updates (unless anonymity is preferred).