Skip to content

Security: spbu-se/spbu_se_site

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security vulnerability in the SE Site project, please report it privately to the SPbSU System Programming Department administration.

Do NOT report security vulnerabilities via public GitHub issues.

Supported versions

Only the latest release (tagged vYYYY.MM.DD on the current branch) receives security fixes.

Disclosure policy

Vulnerabilities are fixed via a dedicated security PR, reviewed, and released as part of the next scheduled release. Critical vulnerabilities may trigger an out-of-cycle release.

Recognition

We thank security researchers who report vulnerabilities responsibly.

Learn more about advisories related to spbu-se/spbu_se_site in the GitHub Advisory Database