Skip to content

Security: SRINIVASTA/SmartBhojan

Security

SECURITY.md

Security Policy 🛡️

We take the security and integrity of Smart Bhojan seriously. Because this application relies heavily on user input parsing via Streamlit and file compilation via ReportLab PDF libraries, we want to proactively prevent risks like cross-site scripting (XSS), dependency vulnerabilities, or HTML injection flaws.


Supported Versions

Only the latest version running on the primary production branch receives security updates.

Version Supported
Main ✅ Yes
< 1.0.0 ❌ No

🚨 Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

If you discover a security flaw or vulnerability within this application, follow these reporting steps:

  1. Draft a private message outlining the vulnerability.
  2. Include a clear description of the issue, step-by-step instructions to reproduce it, and any proof-of-concept scripts or screenshots.
  3. Send your report directly to the repository maintainer via their designated contact method or utilize GitHub's Private Vulnerability Reporting system if enabled on this fork.

Our Response Timeline

  • Acknowledgment: You will receive an acknowledgment of your report within 48 hours.
  • Triage & Fix: We aim to investigate and address confirmed vulnerabilities within 7 to 14 days.
  • Disclosure: Once a fix is pushed to the repository, proper attribution will be provided to the finder in the release updates (unless anonymity is preferred).

There aren't any published security advisories