Skip to content

Security: zeropress-app/zeropress-edge

SECURITY.md

Security Policy

Report a vulnerability privately

Report suspected ZeroPress Edge vulnerabilities through GitHub's private vulnerability reporting form:

Report a vulnerability

Please keep vulnerability details, exploit code, and sensitive information out of public issues, pull requests, and discussions. Use public issues for ordinary bug reports and feature requests that do not disclose a security vulnerability.

What to include

  • The affected Edge release tag or commit, and the Studio version if relevant.
  • The affected feature or endpoint and the configuration needed to reproduce it.
  • Reproduction steps and a minimal proof of concept, using an installation and test data you control.
  • The expected behavior, observed behavior, and potential security impact.
  • Relevant logs or screenshots with secrets, credentials, and personal data removed.

Do not include live Worker secrets, API keys, access tokens, or production data. English and Korean reports are welcome.

Coordinated disclosure

Use the private advisory for follow-up questions and remediation discussions. Please coordinate public disclosure with the maintainers so affected users can receive a fix or mitigation before reproduction details become public.

There aren't any published security advisories