| Version | Supported |
|---|---|
| 0.0.x | ✅ |
We take security seriously at Kartoza. If you discover a security vulnerability in CloudNativeGIS, please report it responsibly.
- Do NOT create a public GitHub issue for security vulnerabilities
- Email us at security@kartoza.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 1 week
- Resolution Timeline: Depends on severity
- Critical: 24-72 hours
- High: 1-2 weeks
- Medium: 2-4 weeks
- Low: Next release cycle
- We follow responsible disclosure practices
- Security advisories will be published after fixes are released
- Credit will be given to reporters (unless anonymity is requested)
When deploying CloudNativeGIS:
- Keep all dependencies updated
- Use HTTPS in production
- Configure proper authentication
- Set appropriate CORS settings
- Use environment variables for secrets
- Regular security audits
Made with ❤️ by Kartoza