Skip to content

Security: Casper-Tech-ke/sportify-api

Security

SECURITY.md

Security Policy

Project: Sportify API
Maintainer: TRABY CASPER · CASPER TECH
Contact: xcasper.space


Supported Versions

Version Supported
1.x (current) ✅ Active

Reporting a Vulnerability

If you discover a security vulnerability in Sportify API, please do not open a public GitHub issue. Instead, report it responsibly using one of the following methods:

  1. GitHub Private Advisory — Open a Security Advisory on this repository
  2. Direct contact — Reach out via xcasper.space

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fix if available

Response Timeline

Stage Timeframe
Acknowledgement Within 48 hours
Initial assessment Within 5 days
Fix or mitigation Within 14 days (depending on severity)
Public disclosure After fix is deployed

Scope

In scope

  • Authentication or token exposure vulnerabilities
  • Server-side injection issues
  • Denial of service vulnerabilities
  • Information disclosure issues

Out of scope

  • Vulnerabilities in Spotify's own platform
  • Issues related to data accuracy or availability
  • Rate limiting bypass (this API intentionally has no rate limits)

Responsible Disclosure

We appreciate responsible disclosure and will acknowledge your contribution in the release notes if you agree. We do not currently offer a bug bounty programme, but we sincerely value the security community's efforts.


© 2025 CASPER TECH · TRABY CASPER

There aren’t any published security advisories