Skip to content

Security: ERPGulf/gulf_payroll

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do NOT open public GitHub issues for security problems.

Report privately via:

  • GitHub: "Report a vulnerability" under the repository's Security tab
  • Email: support@erpgulf.com (subject line starting with "[SECURITY]")

Please include:

  • Affected app and commit
  • Steps to reproduce
  • Impact and any suggested fix

What to Expect

  • Acknowledgment within 3 business days
  • Status update within 10 business days
  • Fix and coordinated disclosure, normally within 90 days

Scope

In scope: ERPGulf apps published in this organization. Out of scope: Frappe/ERPNext core (report to Frappe), and testing against live customer or production systems. Please test only on your own local installation.

Credit

We credit reporters in GitHub Security Advisories and release notes, using the name or handle you prefer.

There aren't any published security advisories