Skip to content

Security: Hsiii/ontrack

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities, leaked credentials, backend abuse paths, or privacy-impacting bugs.

Report security issues by email: its.hsichen@gmail.com

Include:

  • Affected area: iOS, web, Worker API, deployment, or documentation
  • Steps to reproduce
  • Expected impact
  • Any relevant request IDs, endpoints, or logs

Scope

Security reports are welcome for the current main branch and the official OnTrack service at ontrack.hsichen.dev.

Do not run disruptive testing against the production service. For load testing, scanner testing, or exploit validation, use your own fork and deployment unless you have coordinated first.

There aren't any published security advisories