Skip to content

Security: JadenRazo/TicketHacker

SECURITY.md

Security policy

Supported code

Only the latest main branch is considered for security fixes. This repository does not provide a supported public deployment or availability commitment.

Reporting

Use GitHub private vulnerability reporting through the repository's Security tab when available. Otherwise email contact@jadenrazo.dev with the affected path, impact, and a minimal reproduction.

Do not open a public issue containing credentials, tenant or customer data, message or attachment contents, integration secrets, database records, or a working exploit against a reachable service.

Scope

Authentication, tenant isolation, API and WebSocket authorization, chat and bot integrations, attachment handling, automation, AI-provider boundaries, database policies, and CI/release workflows are in scope. Dependency vulnerabilities should also be reported to the relevant upstream project.

There aren't any published security advisories