Skip to content

Security: rizalahmaddd/qris-bridge

Security

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in QRIS Bridge, please report it privately.

Do not open a public GitHub issue. Instead, send an email to:

optimaseoo@gmail.com

We will acknowledge receipt within 48 hours and provide an estimated timeline for a fix.

Scope

The following are in scope:

  • Server-side vulnerabilities that could leak merchant data or secrets
  • Authentication or authorisation bypass in device registration or WebSocket access
  • Webhook signature bypass or HMAC weaknesses
  • Duplicate detection bypass

The following are out of scope:

  • Compromised Android devices (malware, rooted devices)
  • Social engineering attacks
  • OEM battery optimization killing foreground service

Disclosure Policy

  • We will notify you once the vulnerability is confirmed.
  • A fix will be developed and tested privately.
  • Once the fix is released, we will publish an advisory with credit to the reporter (unless anonymity is requested).
  • We ask for a 90-day disclosure window from the date of the first response.

Responsible Disclosure

We ask:

  • Report privately, do not publish before patch
  • Provide sufficient detail for reproduction
  • Do not exploit the vulnerability

There aren't any published security advisories