Security reports apply to only these deployments, to the best of our knowledge:
https://trassenscout.dehttps://staging.trassenscout.de
We are not aware of other instances of this software. Issues observed on other hosts may be forks or unrelated deployments and could be out of scope.
We do not maintain a separate matrix of supported package or dependency versions; please report against what is running on the hosts above.
Please do not open a public GitHub issue for an undisclosed security vulnerability.
Always contact us by email first. Address: local part dev-team, domain fixmycity.de (join with the standard mailbox separator).
If the issue is time-critical, also reach out on Matrix (@tordanstordans:matrix.org) so we notice sooner—still send the full report by email (Matrix is for visibility, not a substitute for the written report).
You may also use GitHub’s private vulnerability reporting: open this repository’s Security tab and choose Report a vulnerability. (How it works)
We will triage the report, ask clarifying questions if needed, and work toward a fix. We aim for coordinated disclosure after a mitigation or release when appropriate.
Some issues may depend on upstream projects; we may forward or coordinate with upstream where it helps.