Forus is operated as one current release. Security fixes are applied to the latest release only.
Releases are published at https://github.com/teamforus/Forus/releases.
If you believe you have found a security or privacy vulnerability in the Forus platform, email security@forus.io.
Do not report it in a public GitHub issue or pull request.
If you can, include:
- the type of vulnerability
- the files involved
- the release tag or commit
- the steps to reproduce it
- the possible impact
Limit your research to what is needed to demonstrate the vulnerability.
- Do not cause harm, interrupt the service, or destroy data.
- Do not access, change, or copy data beyond what is needed to demonstrate the issue.
- Do not misuse data you encounter.
- Use only accounts you own, or accounts you have explicit permission to use.
- Do not publicly disclose the vulnerability before Forus has had a reasonable time to investigate and resolve it.
This policy covers the Forus platform that Forus operates. It does not cover systems of municipalities, suppliers, partners, or other third parties, including systems that connect to Forus. For those systems, follow the security policy of the organization that operates them.
If you are unsure whether a system is in scope, email security@forus.io before you test it.
We appreciate responsible security research and will work with you to investigate and resolve valid reports.
You can expect:
- an acknowledgement of your report within one working day
- an initial assessment within three working days
- updates while we investigate and resolve the issue
- coordination with you before details of a vulnerability are publicly disclosed
If you follow this policy and act in good faith, Forus will not initiate legal action against you for your security research on the Forus platform.
This safe harbor applies only to the Forus platform that Forus operates. Forus cannot give permission to test systems it does not operate.
Give Forus a reasonable time to investigate and resolve the issue before you make information about it public.
Forus will coordinate the timing and form of public disclosure with you. Forus does not publish details of a vulnerability before that coordination, except where disclosure is required by law.
Once an issue has been resolved, the security fix may be described in the release notes.
With your permission, Forus can credit you by name or handle. You may also choose to remain anonymous. Forus will not name you without your permission.