If you discover a security vulnerability within Cosmic-Trajectories, we encourage you to report it as soon as possible. We take security seriously and will work with you to resolve any issues as quickly as possible.
To report a vulnerability, please follow the steps below:
- Email us directly at [email protected] with a clear description of the issue, including steps to reproduce if applicable.
- Do not disclose the vulnerability to the public or other parties until it has been addressed and resolved. This ensures that potential exploits are minimized.
Once a vulnerability is reported, we will investigate the issue and work on a patch. The patch will be released as soon as possible, and the details of the fix will be included in the release notes.
We aim to respond to security issues within 72 hours of receiving a report and will provide an update on the resolution timeline.
We encourage contributors to follow best security practices while working on the Cosmic-Trajectories project. Here are some guidelines:
- Use HTTPS for all external communication and APIs.
- Keep dependencies up to date to mitigate known vulnerabilities.
- Follow secure coding practices to prevent common vulnerabilities like SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF).
- Review and test changes thoroughly before submitting them to ensure that they do not introduce security issues.
Thank you for helping us keep Cosmic-Trajectories secure. We value your contribution and your commitment to making the project a safe space for everyone.