Skip to content

Security: Zeeeepa/surfapp

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

The Deta team takes the security of Surf seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

Please use GitHub's private vulnerability reporting feature:

  1. Navigate to the Security tab of this repository
  2. Click Report a vulnerability
  3. Fill out the vulnerability report form with as much detail as possible

Alternatively, if you cannot use GitHub's reporting feature, please email us at: security@deta.surf

What to Include

When reporting a vulnerability, please include:

  • Description: A clear description of the vulnerability
  • Impact: Potential impact and severity assessment
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code snippets, screenshots, or videos demonstrating the vulnerability
  • Suggested Fix: If you have ideas on how to resolve the issue (optional)
  • Environment Details: Affected versions, operating systems, configurations, etc.

Security Update Process

  1. Acknowledgment: We will acknowledge receipt of your report as soon as possible
  2. Validation: We will validate and reproduce the reported vulnerability
  3. Fix Development: Our team will develop and test a fix
  4. Disclosure: We will coordinate disclosure timing
  5. Release: We will release a security patch and publish an advisory
  6. Credit: We will credit you in our release notes unless you request anonymity

Scope

The following are outside the scope of our security policy:

  • Issues in dependencies (please report these to the respective maintainers)
  • Social engineering attacks
  • Physical security issues
  • Issues affecting outdated or unsupported versions

Bug Bounty Program

We currently do not offer a bug bounty program, but we deeply appreciate security reports which help keep Surf secure.

Public Disclosure Policy

We follow a coordinated disclosure approach:

  • Please allow us reasonable time to address the vulnerability
  • We request that you do not publicly disclose the vulnerability until we have released a fix

Contact


Thank you for helping keep our project and the users safe!

There aren’t any published security advisories