Skip to content

Security: Bike4Mind/bike4mind

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report vulnerabilities privately through either channel:

  • GitHub Private Vulnerability Reporting (preferred) — use the "Report a vulnerability" button under this repository's Security tab. This keeps the report and our coordination private until a fix is released.
  • Emailsecurity@bike4mind.com. Encrypt sensitive details if you can; we will provide a key on request.

Please include, where possible:

  • The type of issue (e.g. injection, authentication bypass, SSRF, privilege escalation).
  • The affected component, file path(s), and version/commit.
  • Step-by-step reproduction, proof-of-concept, or exploit code.
  • The impact — what an attacker can achieve.

What to Expect

  • We will acknowledge your report and give an initial assessment as quickly as we can.
  • We will keep you informed of remediation progress and coordinate a disclosure timeline with you.
  • With your permission, we will credit you when the fix is published.

Scope

This policy covers the code in this repository. Vulnerabilities in the hosted Bike4Mind service (app.bike4mind.com) — as opposed to this open-core codebase — should also be sent to security@bike4mind.com.

Safe Harbor

We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us a reasonable opportunity to remediate before public disclosure.

There aren't any published security advisories