Please do NOT open public GitHub issues for security problems.
Report privately via:
- GitHub: "Report a vulnerability" under the repository's Security tab
- Email: support@erpgulf.com (subject line starting with "[SECURITY]")
Please include:
- Affected app and commit
- Steps to reproduce
- Impact and any suggested fix
- Acknowledgment within 3 business days
- Status update within 10 business days
- Fix and coordinated disclosure, normally within 90 days
In scope: ERPGulf apps published in this organization. Out of scope: Frappe/ERPNext core (report to Frappe), and testing against live customer or production systems. Please test only on your own local installation.
We credit reporters in GitHub Security Advisories and release notes, using the name or handle you prefer.