Skip to content

Security: developmentseed/stac-auth-proxy

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report them privately via GitHub's private vulnerability reporting (the "Report a vulnerability" button on the repository's Security tab).

Please include as much of the following as you can:

  • A description of the issue and its impact (e.g. authentication bypass, filter bypass, data exposure)
  • Steps to reproduce, ideally with a minimal configuration and example requests
  • Affected version(s) and relevant configuration (e.g. enabled filters, upstream STAC API)
  • Any suggested fix or mitigation

What to Expect

  • We aim to acknowledge reports within 5 business days.
  • We will keep you informed as we investigate and work on a fix.
  • Once a fix is released, we will publish a GitHub Security Advisory and, where appropriate, request a CVE. Reporters are credited unless they prefer to remain anonymous.

Please give us a reasonable amount of time to address the issue before any public disclosure.

Supported Versions

Security fixes are applied to the latest release only. Please upgrade to the most recent version before reporting.

Learn more about advisories related to developmentseed/stac-auth-proxy in the GitHub Advisory Database