Files
accounted/SECURITY.md
T
Jakob WennbergandClaude Opus 4.6 f3ec634a46 feat: open-source under AGPL-3.0, redesign UI to grayscale palette, add uncategorize API, fix VAT account names
Add LICENSE (AGPL-3.0-or-later), CONTRIBUTING.md, SECURITY.md, DCO, and NOTICE files.
Rewrite README for open-source audience with self-hosting instructions.
Redesign color palette to grayscale chrome theme across all components.
Add transaction uncategorize API route with tests.
Fix VAT account name mismatches in migration 052.
Improve import page with SIE file support and loading skeleton.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 18:18:11 +01:00

1.3 KiB

Security Policy

Reporting Vulnerabilities

If you discover a security vulnerability in erp-base, please report it responsibly. Do not open a public issue.

Email: security@gnubok.se

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Scope

The following areas are in scope for security reports:

  • Authentication and authorization -- Supabase auth, RLS policies, API route guards
  • Accounting data integrity -- journal entry immutability, period lock enforcement, balance validation
  • Document retention -- 7-year retention enforcement, deletion prevention
  • API routes -- injection, authorization bypass, data leakage
  • Extension system -- privilege escalation, sandbox escape

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 7 days
  • Fix for critical issues: within 30 days
  • Public disclosure: coordinated with the reporter after the fix is released

Safe Harbor

We will not pursue legal action against security researchers who:

  • Act in good faith to avoid harm to users and data
  • Report vulnerabilities promptly and do not exploit them beyond what is necessary to demonstrate the issue
  • Do not access, modify, or delete other users' data
  • Follow the reporting process described above