We take the security of Podr seriously. If you discover a security vulnerability, please follow these steps:
- DO NOT open a public GitHub issue
- Email security details to: kevintcoughlin@users.noreply.github.com
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
For less critical security concerns:
- Open a GitHub Security Advisory
- Or create a private issue using the security label
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
- Status Updates: Every 7 days until resolved
- Fix Timeline: Based on severity (see below)
| Severity | Response Time | Examples |
|---|---|---|
| π΄ Critical | 24-48 hours | RCE, Authentication bypass, Data breach |
| π High | 3-7 days | XSS, CSRF, SQL injection |
| π‘ Medium | 7-14 days | Information disclosure, DoS |
| π’ Low | 14-30 days | Minor information leaks |
We actively maintain security updates for:
| Version | Supported |
|---|---|
| Latest | β Yes |
| < 1.0 | β No |
- Run
yarn auditbefore submitting PRs - Keep dependencies up to date
- Follow secure coding guidelines in CONTRIBUTING.md
- Use TypeScript strict mode
- Validate all user inputs
- Sanitize outputs
- Use Content Security Policy (CSP) headers
- Always use the latest version
- Review security advisories regularly
- Report suspicious behavior
- Enable automatic updates in your deployment
Current security measures in Podr:
- β Automated Dependency Scanning: Dependabot daily scans
- β Code Analysis: CodeQL weekly scans
- β Security Headers: CSP, X-Frame-Options, etc.
- β Audit Logs: CI/CD security audit on every build
- β Minimal Permissions: GitHub Actions use least privilege
- β HTTPS Only: All production traffic encrypted
- β Subresource Integrity: For CDN resources
We appreciate security researchers who responsibly disclose vulnerabilities. Contributors will be acknowledged in:
- Our security advisories
- Release notes
- This document (with permission)
- We follow responsible disclosure practices
- Security fixes are released via GitHub Security Advisories
- CVEs are requested for significant vulnerabilities
- Public disclosure occurs after fix is released and users have time to update
- Email: kevintcoughlin@users.noreply.github.com
- GitHub: @kevintcoughlin
- Security Advisories: View all advisories
Last Updated: October 2025
Thank you for helping keep Podr and its users safe! π