Skip to content

Security: CaptainCheetah978/RGU-NCC-Web-Application

SECURITY.md

Security Policy

Supported Versions

The National Cadet Corps Cadet Management System is currently in active development. Security updates are provided for the following versions:

Version Supported
0.1.x
< 0.1

As the application reaches a stable 1.0.0 release, this table will be updated to reflect long-term support (LTS) versions.

Reporting a Vulnerability

We take the security of cadet data and our management system very seriously. If you discover a security vulnerability within this project, please do not create a public issue. Instead, follow these steps to report it responsibly:

1. Private Vulnerability Reporting (PVR)

Please use GitHub's Private Vulnerability Reporting feature. This allows you to collaborate privately with the maintainers to fix the issue before it is publicly disclosed.

  • Navigate to the Security tab of the repository.
  • Click on Advisories and then Report a vulnerability.

Alternatively, send a direct message to @CaptainCheetah978 with the subject line [SECURITY REPORT].

2. Incident Response Process

Once a vulnerability is reported, our lightweight incident response plan is triggered:

  • Triage: Acknowledgment within 48 hours and initial severity assessment.
  • Isolation: Verification of the exploit in a private fork.
  • Remediation: Development and testing of a security patch.
  • Disclosure: Coordinated disclosure only after the patch is deployed to all active units.

Thank you for helping us keep the National Cadet Corps Cadet Management System secure!

There aren't any published security advisories