Skip to content

Security: QuirkyTurtle94/GnuDash

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Please do NOT open a public GitHub issue for security vulnerabilities.

Instead, please report them via one of the following methods:

  • GitHub Private Vulnerability Reporting: Use the Security Advisories feature to privately report a vulnerability.
  • Email: Contact the maintainers directly at the email associated with the repository.

What to include

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Any potential impact
  • Suggested fix (if applicable)

What to expect

  • We will review and respond to reports as time permits.
  • You will be credited for responsible disclosure (unless you prefer to remain anonymous).

Security Best Practices for Users

  • Keep your dependencies up to date.
  • Never commit sensitive data (e.g., GNUCash database files containing personal financial information) to public repositories.
  • Review the application's access to your local files and ensure it aligns with your expectations.

There aren't any published security advisories