Skip to content

Security: alihamzahq/pulsepass-api

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you believe you have found a security vulnerability in Pulsepass, please do not open a public GitHub issue. Instead, email the maintainer directly at hello@alihamza.dev with:

  • A description of the issue.
  • Steps to reproduce, or a proof-of-concept if you have one.
  • The version / commit SHA you tested against.

You can expect an initial response within a few days. Once the issue is confirmed and a fix is in place, the report will be acknowledged in the release notes (anonymously by default; let me know if you'd like attribution).

Supported versions

This project tracks main only. There are no long-term support branches. Security fixes land on main directly.

Scope

In scope: anything that ships in this repository. Out of scope: vulnerabilities in third-party dependencies — please report those upstream (Laravel, Stripe SDK, Sanctum, etc.).

There aren't any published security advisories