Skip to content

Security: ci4-cms-erp/ci4ms

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security vulnerabilities in ci4ms privately, through GitHub's private vulnerability reporting:

➡️ Report a vulnerability (also reachable from the repository's Security → Advisories → Report a vulnerability button)

This opens a private security advisory that only the maintainers can see, lets us collaborate with you on a fix, credit you, and request a CVE for the issue when it is published.

If you are unable to use GitHub's reporting flow, you may instead email bertugfahriozer@gmail.com.

Do NOT open a public issue or pull request for a security vulnerability — those are visible to everyone before a fix is available.

Please include as much detail as possible:

  • Description of the vulnerability and its root cause (file/line if known)
  • Steps to reproduce (a proof-of-concept helps)
  • Potential impact and affected versions
  • Any suggested remediation
  • Your contact / GitHub handle for credit (optional)

We aim to acknowledge your report within 72 hours and will keep you updated as we work on a fix. We follow coordinated disclosure: please give us reasonable time to release a patch before any public disclosure, and we are happy to coordinate a timeline and re-test patches with you.


Supported Versions

We actively maintain and provide security fixes for the following versions of ci4ms:

  • Latest stable release
  • Previous major release

If you are using an unsupported version, we recommend upgrading to the latest stable version.


Security Updates

Security patches are published as GitHub Security Advisories (with a CVE where applicable) and communicated via the repository's release notes and CHANGELOG.md.


Acknowledgments

Researchers who report valid vulnerabilities are credited in the Security Hall of Fame.


Thank You

Thank you for helping keep ci4ms safe and secure!

Learn more about advisories related to ci4-cms-erp/ci4ms in the GitHub Advisory Database