Email security@appjars.com. The full policy is at https://www.appjars.com/security/.
Please do not report a suspected vulnerability through a public GitHub issue, a discussion, or any other public channel until a fix has been released. A public report without a fix puts every user of the affected AppJar at risk, including you.
A useful report includes:
- The affected AppJar and its exact version
- The Vaadin and Spring Boot versions in use
- What the vulnerability allows an attacker to do
- Steps or a proof of concept that reproduce it
- A suggested mitigation, if you have one
Reports are accepted in English or Spanish.
We acknowledge every report within 5 business days, then send you our assessment, including how we classify the issue, and keep you updated while we work on it. Published advisories credit the reporter unless you would rather they did not.
We ask for a 90-day coordinated disclosure window: 90 days from the day we acknowledge your report, or until a fix is released, whichever comes first. There is no bug bounty program.
In scope: the published AppJars artifacts under the com.appjars group ID, in supported
versions. Security fixes are issued for the latest released version of each AppJar; there are no
long-term support branches.
Out of scope: your own application, third-party dependencies including Vaadin and Spring Boot, our websites and documentation, the customer portal, and attempts to circumvent license checking.
The demo repositories are sample code rather than published artifacts. A security problem in the sample code itself belongs in that demo's issue tracker. A problem in the AppJar the demo depends on goes to security@appjars.com.