Skip to content

Security: sumikkolab/dependa-web

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not open a public issue. Email security@sumikkolab.com with:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected version (shown in Settings > About or Dependa.exe version)

Acknowledgment within 72 hours. Critical issues are prioritized.

Scope

  • Dependa application (GUI and CLI)
  • MSIX package distributed via Microsoft Store
  • Bundled data files (advisories, license definitions)
  • dependa.sumikkolab.com website

Third-party services (OSV API, PyPI, npm registry, NuGet API) are out of scope.

Supported Versions

Version Supported
1.0.x Yes

There aren’t any published security advisories