If you discover a security vulnerability in Alon Sentinel, please report it privately. Do not open a public GitHub issue.
Email: tomislav.nekic12@gmail.com
Subject line: [SECURITY] Brief description
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fix (optional)
We will acknowledge your report within 72 hours and aim to release a fix within 14 days for critical issues.
In scope:
- Authentication and authorization bypasses
- SQL injection or data exposure
- Remote code execution
- Privilege escalation
- Sensitive data leakage in API responses or logs
Out of scope:
- Denial of service against self-hosted instances
- Issues requiring physical access to the server
- Vulnerabilities in dependencies not yet patched upstream
We follow responsible disclosure. Once a fix is released, you are welcome to publish your findings. We will credit you in the release notes unless you prefer anonymity.