Skip to content

Security: bgerd/rgem.io

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Do not open a public issue.

Instead, use one of these methods:

  1. GitHub Security Advisories (preferred): Report a vulnerability
  2. Email: gbaron@gmail.com

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected component(s): backend, frontend, device firmware
  • Potential impact

Scope

The following components are in scope:

  • Backend: Lambda functions, API Gateway configuration, DynamoDB access patterns
  • Frontend: React web application, WebSocket client
  • Device firmware: Arduino sketch, WiFi/WebSocket handling

Response

We will acknowledge receipt within 72 hours and aim to provide an initial assessment within one week.

There aren’t any published security advisories