We release security updates for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
We take security seriously, especially as an enterprise platform with financial services. If you discover a security vulnerability, please report it responsibly.
Please report security vulnerabilities via email to: wahidyankf@gmail.com
Please include the following information in your report:
- Description of the vulnerability: What is the security issue?
- Steps to reproduce: How can we reproduce the vulnerability?
- Potential impact: What could an attacker do with this vulnerability?
- Affected components: Which parts of the system are affected?
- Suggested fix (if any): Do you have suggestions for fixing the issue?
- Your contact information: How can we reach you for follow-up?
You can expect:
- Initial Response: Within 48 hours of your report
- Status Update: Within 5 business days with assessment and timeline
- Regular Updates: We will keep you informed of progress toward a fix
- Acknowledgment: We will acknowledge receipt of your report within 48 hours
- Investigation: We will investigate and assess the severity of the vulnerability
- Fix Development: We will develop and test a fix (timeline depends on severity)
- Security Release: We will release a security update as a patch version
- Public Disclosure: We will publicly disclose the vulnerability after the fix is available and users have had time to update
We assess vulnerabilities using the following severity levels:
- Critical: Immediate threat to data integrity, confidentiality, or availability
- High: Significant security impact requiring urgent attention
- Medium: Security issue that should be addressed in next release
- Low: Minor security concern with limited impact
As an enterprise platform with financial services, we follow these security principles:
- Secure by Default: Security features enabled out of the box
- Principle of Least Privilege: Components have minimal necessary permissions
- Defense in Depth: Multiple layers of security controls
- Regular Security Audits: Periodic review of code and infrastructure
- Dependency Management: Regular updates of dependencies with known vulnerabilities
Security fixes are released as patch versions (e.g., 1.2.3 → 1.2.4).
How to stay informed:
- Watch this repository for releases
- Subscribe to GitHub release notifications
This security policy applies to:
- All code in this repository
- Official Docker images and deployments
- Official npm packages published under
@open-sharia-enterprisescope
Out of scope:
- Vulnerabilities in dependencies (please report to the respective projects)
- Theoretical vulnerabilities without proof of concept
- Issues that require physical access to the server
- Social engineering attacks
We appreciate security researchers who help us maintain the security of our project. With your permission, we will acknowledge your contribution in:
- Security advisory (if applicable)
- CONTRIBUTORS.md file
- Release notes
Thank you for helping keep Open Sharia Enterprise secure!