Skip to content

Security: mdbase-dev/mdbase-reader

SECURITY.md

Security policy

mdbase Reader is prerelease software.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository. Include:

  • the affected component (web app, browser extension, Zotero exporter) and version or commit;
  • the prerequisites and smallest reproducible sequence;
  • the impact you observed or believe is possible; and
  • relevant logs or artifacts with credentials, collection paths, and record content removed.

Do not access data that is not yours, degrade a service, or publish details before a coordinated disclosure date. Response times are goals rather than a service-level agreement while the project is maintained by a small team.

Supported versions

Only the latest release of each component and the current main branch receive fixes.

There aren't any published security advisories