Skip to content

Security: jp1337/momo

SECURITY.md

Security Policy

Supported versions

Security fixes are released for the latest published version. Always run the most recent release.

Version Supported
Latest ✅
Older ❌

Reporting a vulnerability

Report it privately through GitHub's private vulnerability reporting ("Report a vulnerability" on the Security tab). Never in a public issue.

Especially valued: one user reading or changing another user's data, bypasses of login, 2FA or passkeys, leaked API keys or sessions, and webhooks that reach internal hosts.

Research is welcome, and unpaid

You may test Momo and report what you find. There is no payment: Momo is a volunteer project, and every report serves the people who rely on it. With your consent, we credit you in the advisory and below. Test on your own installation, never on other people's.

Response times

Step Within
Acknowledge your report 48 hours
Assess it and tell you the plan 7 days
Release a fix for a critical or high issue 14 days

Momo is maintained in spare time; these are commitments, and when one slips you hear why.

Security acknowledgements

None yet.

There aren't any published security advisories