LearnHub is currently under active local development and does not yet have stable release branches.
| Version | Supported |
|---|---|
| main | ✅ |
| older branches | ❌ |
If you discover a security vulnerability in LearnHub, please do not open a public GitHub issue, discussion, or pull request.
Instead, report it privately by emailing:
Please include as much detail as possible:
- A clear description of the issue.
- Steps to reproduce the vulnerability.
- The affected file, route, feature, or component.
- The possible impact.
- Screenshots, logs, or proof-of-concept details if available.
After receiving a security report:
- The report will be reviewed as quickly as possible.
- Acknowledgement will usually be sent within 72 hours.
- Valid reports will be investigated privately before any public disclosure.
- A fix timeline will depend on the severity and scope of the issue.
Please avoid public disclosure until the issue has been reviewed and a fix or mitigation is ready.
Responsible disclosure helps protect users, contributors, and the project.
This policy applies to:
- Authentication and authorization flaws
- Sensitive data exposure
- Injection vulnerabilities
- File upload vulnerabilities
- Dependency-related security risks
- Any issue that could compromise confidentiality, integrity, or availability