Skip to content

Security: Guayamose/Foodly

Security

SECURITY.md

Security Policy

Foodly handles user accounts, uploaded ingredient photos, generated recipes, preferences, allergies, and meal-planning data. Security reports are taken seriously.

Supported Versions

Version Supported
v0.1.x Yes
Older versions No

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Use GitHub's private vulnerability reporting or security advisory flow for this repository when available. If that is not available, contact the repository maintainers directly through GitHub with enough detail to reproduce and evaluate the issue.

Helpful details include:

  • A clear description of the vulnerability.
  • Steps to reproduce it.
  • Affected pages, routes, or user flows.
  • Any proof-of-concept code or screenshots.
  • Potential impact and suggested mitigation, if known.

Response Expectations

  • We aim to acknowledge valid reports within 7 days.
  • We aim to provide a first assessment within 14 days.
  • Confirmed vulnerabilities will be prioritized based on severity and user impact.

Scope

Security-sensitive areas include:

  • Authentication and account management.
  • User-uploaded photos and file handling.
  • AI prompts and generated content handling.
  • Allergy and preference data.
  • Recipe ownership, favorites, reviews, and meal schedules.
  • API keys, credentials, environment variables, and deployment configuration.

There aren't any published security advisories