Do not report security vulnerabilities through public GitHub issues.
If you discover a security vulnerability in the Lean Storytelling App, please report it privately to our security team:
Email: security@leanstorytelling.app GPG Key: Download our public GPG key
When reporting a vulnerability, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Any relevant proof-of-concept code
- Your contact information (optional)
- Any potential mitigations you've identified
- Acknowledgment: You will receive an acknowledgment of your report within 48 hours
- Assessment: Our security team will assess the vulnerability and determine its impact
- Resolution: We will work on a fix and provide you with updates on our progress
- Disclosure: After the vulnerability is fixed, we will publicly disclose it (with credit to you, unless you prefer to remain anonymous)
Only the latest major version of the Lean Storytelling App receives security updates. We recommend always using the latest version.
| Version | Supported |
|---|---|
| 0.4.x | ✅ Yes |
| 0.3.x | ❌ No |
| < 0.3 | ❌ No |
- Always use the latest version of the application
- Use strong, unique passwords
- Enable two-factor authentication when available
- Regularly review your account activity
- Report any suspicious activity immediately
- Follow our Contribution Guidelines
- Never commit sensitive information (passwords, API keys) to the repository
- Use environment variables for configuration
- Follow secure coding practices
- Keep dependencies updated
We follow a responsible disclosure policy:
- Initial Report: Vulnerability is reported privately
- Triage: We acknowledge receipt within 48 hours
- Investigation: We investigate and develop a fix (typically within 7-14 days)
- Patch: We release a security patch
- Disclosure: We publicly disclose the vulnerability after users have had time to update
We would like to thank the following security researchers for responsibly disclosing vulnerabilities:
- [Your Name Here] - [Vulnerability Type]
For security-related questions that are not vulnerabilities, you can contact us at:
- General Security Questions: security-questions@leanstorytelling.app
- GPG Fingerprint:
ABCD 1234 EFGH 5678 IJKL MNOP QRST UVWX YZ
Thank you for helping keep the Lean Storytelling App and its users safe!