Skip to content

Security: POLPROG-TECH/LocaleSync

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x ✅ Current release

Reporting a Vulnerability

If you discover a security vulnerability in LocaleSync, please report it responsibly.

Do not open a public issue.

Instead, please email contact@polprog.pl with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

We will acknowledge your report within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.

Scope

Security concerns relevant to LocaleSync include:

  • Credential handling - leakage of translation provider API keys in logs, UI, or error pages
  • Path traversal when resolving locale directories or output paths
  • Output safety - XSS or HTML injection in the rendered web dashboard
  • Placeholder tampering - unsafe interpolation that could alter translation semantics
  • Sensitive data leakage - internal paths, tokens, or config values exposed in UI or logs
  • Dependency vulnerabilities in third-party packages

Disclosure Policy

We follow coordinated disclosure:

  1. Report the issue privately via the contact above.
  2. We confirm receipt and begin investigation.
  3. Once a fix is released, we publicly acknowledge the reporter (with their consent).

There aren’t any published security advisories