Skip to content

Security: BUDEGlobalEnterprise/bude-global-implementation

SECURITY.md

Security Policy

Supported Versions

The following versions of BUDE Global Enterprise's projects and implementations are currently supported with security updates:

Version Supported
Frappe Framework / ERPNext v15.x
Custom BUDE Marketplace App
IoT/RFID Integration Modules

Reporting a Vulnerability

We take the security of our systems seriously, and we value the input of security researchers and the developer community.

How to Report a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report suspected security vulnerabilities privately to:

What to Include in Your Report

To help us understand and resolve the issue quickly, please include:

  1. Description of the vulnerability and its potential impact
  2. Steps to reproduce the issue
  3. Affected versions and components
  4. Any proof-of-concept code or screenshots
  5. Your suggested fix (if any)

Our Commitment

  • We will acknowledge receipt of your vulnerability report within 48 hours
  • We will provide a more detailed response within 5 business days
  • We will keep you informed about our progress throughout the process
  • We will credit you for your discovery (unless you prefer to remain anonymous)

Response Timeline

Action Timeline
Initial response to your report 2 business days
confirmation of vulnerability 5 business days
Resolution implementation Depends on complexity
Public disclosure After patch is available

Disclosure Policy

We follow responsible disclosure practices:

  • We will not take legal action against you for reporting vulnerabilities if you make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
  • We will work with you to understand and resolve the issue quickly
  • We will publicly acknowledge your contribution after the vulnerability has been resolved (unless you prefer to remain anonymous)

Scope

This security policy applies to:

  • All BUDE Global Enterprise repositories
  • ERPNext implementation frameworks
  • Custom Frappe apps developed by BUDE Global
  • Documentation and deployment scripts

Out of Scope

The following are generally out of scope for our vulnerability reporting:

  • Physical security attacks
  • Social engineering attacks
  • Denial of service attacks
  • Issues related to third-party services we integrate with (please report those directly to the affected service)

Thank you for helping keep BUDE Global Enterprise and our users safe!

There aren't any published security advisories