🚨 Seenly Social — Security Policy & Guidelines
Security is foundational to the Seenly ecosystem. We welcome responsible disclosure from security researchers and the open-source community.
---
1. Supported Versions
| Version | Supported | | :--- | :--- | | v1.0.x (Current) | ✅ Supported | | < v1.0 | ❌ End of Life |
---
2. Reporting a Vulnerability
If you discover a security vulnerability within Seenly Social, please follow these steps:
1. Do not create a public GitHub issue. 2. Send a detailed report to our security team at: security@seenly.social (or via GitHub Private Vulnerability Reporting). 3. Include: - Description of the vulnerability. - Proof of Concept (PoC) or reproduction steps. - Potential impact assessment. 4. We acknowledge all reports within 24 hours and will provide regular status updates until resolution.
---
3. Security Hardening Measures
- Content Security Policy (CSP): Strict resource limits preventing unauthorized script injection. - Cross-Site Scripting (XSS): Strict React DOM sanitization and no `eval()` execution. - Cross-Origin Resource Sharing (CORS): Restricted to authorized Seenly domains. - Rate Limiting: Applied to all authentication, upload, and API endpoints. - HTTPS & TLS: Enforced across all web and WebSocket communication channels.