Skip to content

Security: davevancauwenberghe/Stationsbord

SECURITY.md

Security Policy

Supported Versions

The following versions of Stationbord are currently supported with security updates:

Version Supported
0.x.x

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Do not open a public GitHub issue for security-related problems.

Instead:

  1. Open a private security advisory on GitHub (preferred), or
  2. Contact the maintainer directly.

When reporting, please include:

  • A clear description of the issue
  • Steps to reproduce (if applicable)
  • Potential impact
  • Any relevant logs, screenshots, or PoC code

You can expect:

  • An acknowledgement within a few days
  • A best-effort fix for supported versions
  • Responsible disclosure once the issue is resolved

Scope

This policy covers:

  • The Stationbord application code
  • API usage and request handling
  • Docker images (if used)
  • Configuration and environment variable handling

It does not cover:

  • Issues in third-party services (such as the iRail API itself)
  • Problems caused by misconfigured self-hosted environments

Thanks

Responsible disclosure helps keep the project safe for everyone.
Your effort is appreciated.

There aren’t any published security advisories