Please do not report security vulnerabilities through public GitHub issues.
If you discover a security vulnerability in STARTcloud UI, please report it responsibly:
- Go to the GitHub Security Advisory page
- Click "Report a vulnerability"
- Fill out the advisory form with detailed information
- Submit the advisory
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Affected versions (if known)
- Suggested fix (if you have one)
Due to limited development resources, please understand that:
- Initial Response: we aim to acknowledge receipt within 48–72 hours
- Assessment: initial assessment within about a week
- Resolution: timeline depends on severity, typically 1–4 weeks
- Disclosure: coordinated disclosure after a fix is available
- Critical: immediate attention (e.g. XSS enabling account takeover)
- High: quick response (authentication / session handling flaws)
- Medium: standard timeline
- Low: lower priority
STARTcloud UI is a client-side app that talks to the backend that serves it over a relative /api surface, and to the STARTcloud identity provider for browser sign-in. The security-relevant areas are:
- Cross-site scripting (XSS) — unsafe rendering of untrusted data. React escapes by default, and
dangerouslySetInnerHTMLis disallowed by lint (react/no-danger). - Auth / session handling — sessions use same-origin, credentialed requests or PKCE + DPoP against the identity provider; watch for token or session leakage into logs, storage, or third parties.
- Dependency & supply chain — vulnerable npm packages. Dependabot and CodeQL run against this repository.
- Content injection — data rendered from the API (names, logs, config values) must not be able to break out of its context.
- Keep updated — always run the latest stable release
- Serve over HTTPS with appropriate security headers (e.g. a Content Security Policy)
- Keep dependencies patched
We appreciate the security research community's efforts. Responsible disclosure helps protect all users.
Contributors who responsibly report security vulnerabilities will be acknowledged here (with their permission):
- No vulnerabilities reported yet
This security policy may be updated as the project evolves. Check back periodically for changes.