Skip to content

Security: LudiceTeam/Ludice

Security

SECURITY.md

πŸ”’ Security Policy

Supported Versions

We only provide security updates for the following versions:

Version Supported
1.x βœ… Supported

πŸ“’ Reporting a Vulnerability

If you discover a security vulnerability in Ludice, please do not open a public issue.
Instead, report it privately to the maintainers:

We will respond within 48 hours and aim to resolve critical issues within 7 days.


🧩 Guidelines for Responsible Disclosure

When reporting, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact if exploited
  • Any suggested fix or patch

🧱 Security Practices

We regularly:

  • Run static code analysis using Bandit
  • Scan dependencies with Dependabot
  • Review code changes manually before merging

All credentials and API tokens are stored securely using environment variables.


πŸ§‘β€πŸ’» Contributors

If you are fixing a vulnerability, please do not open a pull request directly.
Contact the maintainers first, and we’ll coordinate a secure patch release.

There aren’t any published security advisories