Skip to content

Security: davidesb007/KashCal

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
16.x

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

How to Report

Please use GitHub Security Advisories to report vulnerabilities privately.

Do NOT:

  • Open a public GitHub issue for security vulnerabilities
  • Disclose the vulnerability publicly before it has been addressed

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

What to Expect

  1. Acknowledgment: We will acknowledge receipt within 48 hours
  2. Assessment: We will assess the vulnerability and determine severity
  3. Fix: We will work on a fix for confirmed vulnerabilities
  4. Disclosure: Once fixed, we will coordinate disclosure with you

Scope

This security policy applies to:

  • The KashCal Android application
  • The official repository at github.com/KashCal/KashCal

Out of scope:

  • Third-party services (iCloud, CalDAV servers)
  • Issues in dependencies (report to the respective projects)

Security Best Practices for Users

  • Keep KashCal updated to the latest version
  • Use a strong, unique app-specific password for iCloud sync
  • Do not share your iCloud credentials
  • Review calendar permissions granted to the app

There aren’t any published security advisories