Skip to content

Security: CarlosFranzetti/GotsToGo

Security

SECURITY.md

Security Policy

Supported version

Security fixes are applied to the current default branch and the live deployment.

Report a vulnerability

Do not open a public issue for vulnerabilities involving user identity, precise location, private reports, authentication, or database access.

Use GitHub's private vulnerability reporting feature if it is enabled. Otherwise, contact the repository owner through the contact method listed on the GitHub profile.

Include reproduction steps, impact, and a minimal proof of concept without real location histories or personal information.

Privacy and data safety

Collect the minimum location data needed for a search. Avoid storing precise location history unless the user knowingly opts in. Validate user-submitted restroom details and strip unsafe content before displaying it.

Never commit .env files, API keys, service-role keys, database credentials, or deployment tokens. Revoke and rotate any exposed credential.

There aren't any published security advisories