Skip to content

Security: almeidamarcell/marapulse

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Marapulse, please report it responsibly. Do not open a public GitHub issue.

Email: almeidamarcell@gmail.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 7 days
  • Fix or mitigation: within 90 days (critical issues prioritized)

Scope

This policy covers:

  • The Marapulse application code in this repository
  • The hosted Marapulse service

Out of scope:

  • Third-party dependencies (report to the upstream project)
  • Self-hosted instances with custom modifications
  • Social engineering attacks

Recognition

Security researchers who report valid vulnerabilities will be credited in the release notes (unless they prefer to remain anonymous).

Supported Versions

Version Supported
Latest Yes
Older No

We recommend always running the latest version.

There aren’t any published security advisories