| Version | Supported |
|---|---|
| 1.x | ✅ Yes |
| < 1.0 | ❌ No |
Please do NOT open a public GitHub issue for security vulnerabilities.
If you discover a security vulnerability in NeuroStride, please report it responsibly:
- Email the maintainer directly (check the GitHub profile for contact info).
- Include a clear description of the vulnerability, steps to reproduce, and potential impact.
- We will acknowledge your report within 72 hours and aim to patch critical issues within 7 days.
The following are considered in-scope:
- Authentication bypass or token forgery
- SQL injection or data leakage
- Unsafe handling of patient health data (PHI)
- Exposed API keys or credentials
- Issues in third-party dependencies (please report those upstream)
- Social engineering attacks
- Denial-of-service via resource exhaustion
Thank you for helping keep NeuroStride and its users safe.