Skip to content

Security: artwork-software/artwork

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use one of these private channels:

Please include as much of the following as you can:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce, or a proof of concept
  • The affected version or commit, and your installation method (Docker or standalone)

We will confirm receipt of your report, keep you informed about the progress, and credit you in the fix release if you wish.

Supported Versions

Security fixes are provided for the latest release. If you run an older version, please update to the current release before reporting, as the issue may already be fixed.

Scope

artwork is self-hosted software. Issues caused purely by misconfiguration of an individual installation (e.g. exposed .env files, missing TLS) are outside the scope of this policy — but if artwork's defaults or documentation make such a misconfiguration likely, we do want to hear about it.

There aren't any published security advisories