Skip to content

Security: gamonoid/icehrm

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release receives security updates.

Version Supported
36.0.x ✅
< 36.0 ❌

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Report vulnerabilities privately by emailing team@icehrm.com. Include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof-of-concept (kept confidential)
  • The IceHRM version you tested against

What to expect:

  • Acknowledgement within 3 business days
  • A status update within 14 days (accepted, needs more info, or declined)
  • Credit in the release notes and security advisory if the report is accepted and a CVE is filed

We aim to release a patch within 90 days of a confirmed vulnerability. We ask that you hold public disclosure until a fix is available and coordinate the timing with us.

There aren't any published security advisories