Skip to content

Security: FixMyBerlin/trassenscout

SECURITY.md

Security Policy — Trassenscout

Supported deployments

Security reports apply to only these deployments, to the best of our knowledge:

  • https://trassenscout.de
  • https://staging.trassenscout.de

We are not aware of other instances of this software. Issues observed on other hosts may be forks or unrelated deployments and could be out of scope.

We do not maintain a separate matrix of supported package or dependency versions; please report against what is running on the hosts above.

How to report a vulnerability

Please do not open a public GitHub issue for an undisclosed security vulnerability.

Always contact us by email first. Address: local part dev-team, domain fixmycity.de (join with the standard mailbox separator).

If the issue is time-critical, also reach out on Matrix (@tordanstordans:matrix.org) so we notice sooner—still send the full report by email (Matrix is for visibility, not a substitute for the written report).

You may also use GitHub’s private vulnerability reporting: open this repository’s Security tab and choose Report a vulnerability. (How it works)

What to expect

We will triage the report, ask clarifying questions if needed, and work toward a fix. We aim for coordinated disclosure after a mitigation or release when appropriate.

Some issues may depend on upstream projects; we may forward or coordinate with upstream where it helps.

There aren't any published security advisories