Skip to content

Security: tfgrid-studio/tfgrid-erpnext

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

TFGrid Studio takes security seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

Email: security@tfgrid.studio

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

What to Expect

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Resolution Timeline: Depends on severity
  • Credit: Security researchers will be credited (if desired)

Please Do NOT

  • ❌ Create public GitHub issues for security vulnerabilities
  • ❌ Publicly disclose the vulnerability before we've had a chance to fix it
  • ❌ Exploit the vulnerability beyond what's necessary to demonstrate it

Responsible Disclosure

We follow coordinated disclosure:

  1. Report the issue to us privately
  2. We'll work on a fix
  3. We'll release the fix
  4. Public disclosure (with credit to reporter)

Security Updates

Security fixes are released as soon as possible and announced via:

  • GitHub Security Advisories
  • Release notes

Thank you for helping keep TFGrid Studio secure!

There aren’t any published security advisories