Skip to content

Security: sudo-Harshk/NoteDiscovery

Security

SECURITY.md

Security Policy

NoteDiscovery is a self-hosted app. Please report vulnerabilities privately so they can be fixed before they are discussed in public.

How to report

Use GitHub's private vulnerability reporting on this repository. That creates a private draft advisory — a private conversation with me, not a public disclosure.

Report a vulnerability

Do not open a public issue with technical details, proof-of-concept code, or payloads.

Include:

  • NoteDiscovery version (or commit) you tested
  • A short description of the issue
  • Steps to reproduce on a local instance
  • What an attacker could do with it

Scope

In scope: security bugs in NoteDiscovery itself (latest release).

Out of scope: deployment/configuration issues (for example exposing an instance to the internet without auth), social engineering, and findings that only affect third-party plugins or unmodified upstream dependencies.

What happens next

This is a spare-time hobby project. I will acknowledge the report when I can. Draft advisories stay private: I will not request CVE IDs or publish public security advisories. If the issue is valid, I will fix it and include it in a normal release.

Please do not disclose it publicly until a release is out, or until we agree otherwise.

Thanks for reporting issues responsibly.

There aren't any published security advisories