Skip to content

Security: FieldmouseWorks/consolebook

SECURITY.md

Security Policy

Current status

Consolebook is pre-alpha and has no production-ready release. Do not use the current repository to store or process personnel or training records.

Reporting a vulnerability

Do not post credentials, personal information, private records, or exploit details in a public issue.

Use the repository's private vulnerability reporting form. It is enabled and sends the report privately to repository maintainers.

Scope

Security work includes:

  • authentication and session handling;
  • authorization and assignment scope;
  • immutable record enforcement;
  • attachment handling;
  • structured exports;
  • backup and restore;
  • audit integrity;
  • setup and recovery tokens; and
  • prevention of sensitive data in logs.

A supported-version policy will be published with the first production-capable release.

There aren't any published security advisories