The following versions of BUDE Global Enterprise's projects and implementations are currently supported with security updates:
| Version | Supported |
|---|---|
| Frappe Framework / ERPNext v15.x | ✅ |
| Custom BUDE Marketplace App | ✅ |
| IoT/RFID Integration Modules | ✅ |
We take the security of our systems seriously, and we value the input of security researchers and the developer community.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report suspected security vulnerabilities privately to:
- Email: budeglobalerp@gmail.com
- PGP Key: Available upon request
To help us understand and resolve the issue quickly, please include:
- Description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Affected versions and components
- Any proof-of-concept code or screenshots
- Your suggested fix (if any)
- We will acknowledge receipt of your vulnerability report within 48 hours
- We will provide a more detailed response within 5 business days
- We will keep you informed about our progress throughout the process
- We will credit you for your discovery (unless you prefer to remain anonymous)
| Action | Timeline |
|---|---|
| Initial response to your report | 2 business days |
| confirmation of vulnerability | 5 business days |
| Resolution implementation | Depends on complexity |
| Public disclosure | After patch is available |
We follow responsible disclosure practices:
- We will not take legal action against you for reporting vulnerabilities if you make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
- We will work with you to understand and resolve the issue quickly
- We will publicly acknowledge your contribution after the vulnerability has been resolved (unless you prefer to remain anonymous)
This security policy applies to:
- All BUDE Global Enterprise repositories
- ERPNext implementation frameworks
- Custom Frappe apps developed by BUDE Global
- Documentation and deployment scripts
The following are generally out of scope for our vulnerability reporting:
- Physical security attacks
- Social engineering attacks
- Denial of service attacks
- Issues related to third-party services we integrate with (please report those directly to the affected service)
Thank you for helping keep BUDE Global Enterprise and our users safe!