Skip to content

Security: kartoza/CloudNativeGIS

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
0.0.x ✅

Reporting a Vulnerability

We take security seriously at Kartoza. If you discover a security vulnerability in CloudNativeGIS, please report it responsibly.

How to Report

  1. Do NOT create a public GitHub issue for security vulnerabilities
  2. Email us at security@kartoza.com with:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

What to Expect

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Resolution Timeline: Depends on severity
    • Critical: 24-72 hours
    • High: 1-2 weeks
    • Medium: 2-4 weeks
    • Low: Next release cycle

Disclosure Policy

  • We follow responsible disclosure practices
  • Security advisories will be published after fixes are released
  • Credit will be given to reporters (unless anonymity is requested)

Security Best Practices

When deploying CloudNativeGIS:

  1. Keep all dependencies updated
  2. Use HTTPS in production
  3. Configure proper authentication
  4. Set appropriate CORS settings
  5. Use environment variables for secrets
  6. Regular security audits

Made with ❤️ by Kartoza

There aren't any published security advisories