Security fixes are prepared for the current release and the current main
branch. Upgrade to the latest FoxDesk release before reporting a problem that may
already be fixed.
Use GitHub private vulnerability reporting. Do not open a public issue or discussion for a suspected vulnerability.
Include:
- affected FoxDesk version and deployment environment;
- the permissions required to reproduce the issue;
- clear reproduction steps and expected impact;
- a minimal proof of concept without real customer data;
- any suggested mitigation, if known.
Remove API tokens, passwords, email contents, personal information, and production identifiers from the report. We will confirm receipt as soon as practical and coordinate disclosure after a fix is available.
This policy covers the self-hosted code in this repository. FoxDesk Cloud reports should use the security contact published on foxdesk.net.