Skip to content

Security: ERM-Systems/ERM

Security

SECURITY.md

Security Policy

Supported Versions

We actively maintain the Development branch with security patches. Only the latest stable release receives security updates.

Version Supported
Latest

Reporting a Vulnerability

If you discover a security vulnerability in ERM, please report it privately before disclosing it publicly.

How to report

Please report vulnerabilities via the GitHub Security Advisory system.

Do not use the public issue tracker for vulnerability reports.

What to include

  • A clear description of the vulnerability
  • Steps to reproduce (if applicable)
  • Potential impact
  • Any suggested mitigation or fix

Response Timeline

  • Acknowledgment within 48 hours of your report
  • Investigation within 5 business days
  • Fix deployed as soon as a patch is ready, coordinated with the reporter

Scope

This policy covers:

  • The ERM Discord bot and its source code
  • The internal FastAPI API
  • Official deployment infrastructure maintained by ERM Systems

Third-party integrations (Discord, MongoDB, GitHub Actions) are subject to their own security policies.


Responsible Disclosure

We ask that you:

  • Give us a reasonable amount of time to fix the issue before disclosing it publicly
  • Make every effort to minimise any disruption caused by the disclosure
  • Avoid exploiting the vulnerability beyond what is necessary to demonstrate it

We thank security researchers who help keep ERM and its users safe.

There aren't any published security advisories