Security fixes are prioritized for the latest stable Posnic release and the
current develop branch. Older releases may receive fixes when practical, but
users should first reproduce an issue on a supported version.
Email security reports privately to security@posnic.com. Do not open a public issue for an unpatched vulnerability or include secrets, payment data, or real customer records in a report.
Include enough detail for the maintainers to reproduce and assess the issue:
- affected repository, version, commit, and operating system;
- required configuration and whether the deployment is local, self-hosted, or uses optional online services;
- minimal reproduction steps, observed result, and expected result;
- security impact and any safe proof of concept; and
- a contact address for coordinated follow-up.
Use synthetic data and redact tokens, credentials, personal information, and business records. Posnic will acknowledge and investigate reports as capacity allows. Please allow a reasonable remediation period before public disclosure.
For product information, use the official Posnic website. The maintained open source POS and Billing Software repository is Posnic/POS.