We actively maintain the Development branch with security patches.
Only the latest stable release receives security updates.
| Version | Supported |
|---|---|
| Latest | ✅ |
If you discover a security vulnerability in ERM, please report it privately before disclosing it publicly.
Please report vulnerabilities via the GitHub Security Advisory system.
Do not use the public issue tracker for vulnerability reports.
- A clear description of the vulnerability
- Steps to reproduce (if applicable)
- Potential impact
- Any suggested mitigation or fix
- Acknowledgment within 48 hours of your report
- Investigation within 5 business days
- Fix deployed as soon as a patch is ready, coordinated with the reporter
This policy covers:
- The ERM Discord bot and its source code
- The internal FastAPI API
- Official deployment infrastructure maintained by ERM Systems
Third-party integrations (Discord, MongoDB, GitHub Actions) are subject to their own security policies.
We ask that you:
- Give us a reasonable amount of time to fix the issue before disclosing it publicly
- Make every effort to minimise any disruption caused by the disclosure
- Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
We thank security researchers who help keep ERM and its users safe.