Skip to content

Security: AppJars/.github

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Email security@appjars.com. The full policy is at https://www.appjars.com/security/.

Please do not report a suspected vulnerability through a public GitHub issue, a discussion, or any other public channel until a fix has been released. A public report without a fix puts every user of the affected AppJar at risk, including you.

A useful report includes:

  • The affected AppJar and its exact version
  • The Vaadin and Spring Boot versions in use
  • What the vulnerability allows an attacker to do
  • Steps or a proof of concept that reproduce it
  • A suggested mitigation, if you have one

Reports are accepted in English or Spanish.

What to expect

We acknowledge every report within 5 business days, then send you our assessment, including how we classify the issue, and keep you updated while we work on it. Published advisories credit the reporter unless you would rather they did not.

We ask for a 90-day coordinated disclosure window: 90 days from the day we acknowledge your report, or until a fix is released, whichever comes first. There is no bug bounty program.

Scope

In scope: the published AppJars artifacts under the com.appjars group ID, in supported versions. Security fixes are issued for the latest released version of each AppJar; there are no long-term support branches.

Out of scope: your own application, third-party dependencies including Vaadin and Spring Boot, our websites and documentation, the customer portal, and attempts to circumvent license checking.

The demo repositories are sample code rather than published artifacts. A security problem in the sample code itself belongs in that demo's issue tracker. A problem in the AppJar the demo depends on goes to security@appjars.com.

There aren't any published security advisories