Skip to content

Security: udaycodespace/learnhub

Security

SECURITY.md

Security Policy

Supported Versions

LearnHub is currently under active local development and does not yet have stable release branches.

Version Supported
main
older branches

Reporting a Vulnerability

If you discover a security vulnerability in LearnHub, please do not open a public GitHub issue, discussion, or pull request.

Instead, report it privately by emailing:

udaysomapuram@gmail.com

Please include as much detail as possible:

  • A clear description of the issue.
  • Steps to reproduce the vulnerability.
  • The affected file, route, feature, or component.
  • The possible impact.
  • Screenshots, logs, or proof-of-concept details if available.

What to Expect

After receiving a security report:

  • The report will be reviewed as quickly as possible.
  • Acknowledgement will usually be sent within 72 hours.
  • Valid reports will be investigated privately before any public disclosure.
  • A fix timeline will depend on the severity and scope of the issue.

Disclosure Policy

Please avoid public disclosure until the issue has been reviewed and a fix or mitigation is ready.

Responsible disclosure helps protect users, contributors, and the project.

Scope

This policy applies to:

  • Authentication and authorization flaws
  • Sensitive data exposure
  • Injection vulnerabilities
  • File upload vulnerabilities
  • Dependency-related security risks
  • Any issue that could compromise confidentiality, integrity, or availability

There aren't any published security advisories