Skip to content

Security: sprahasingh/WorkNest

SECURITY.md

Security

WorkNest is a portfolio project, but it is built to keep each organization's data apart, and security reports are welcome.

Reporting a problem

Please don't open a public issue for a security problem. Use GitHub's private "Report a vulnerability" option on the Security tab of this repository, or email the address on the author's GitHub profile. A short description and the steps to reproduce are enough.

I'll reply as soon as I can, and I'll say when it is fixed.

What is in scope

  • Reading or changing another organization's data
  • Getting around roles (a member doing what only admins can)
  • Taking over an account, or getting a sign-in token or session
  • Getting a paid plan without paying

Good to know

  • Payments run in Razorpay's test mode, so no real money moves.
  • Uploaded files are private and are not scanned for content.

There aren't any published security advisories