We take security seriously. The following versions of PlayBharat are currently supported with security updates:
| Version | Supported |
|---|---|
| 1.0.x | β Fully Supported |
| < 1.0 | β No Longer Supported |
If you discover a security vulnerability in PlayBharat, please report it responsibly:
- Email: aniket.kumar.devpro@gmail.com
- Subject: [SECURITY] PlayBharat Vulnerability Report
- Response Time: Within 48 hours
Please provide the following information:
- Detailed description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Suggested fix (if available)
- Your contact information
- User authentication and authorization
- File upload vulnerabilities
- SQL injection possibilities
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Data exposure issues
- Admin panel security
- Keep your credentials secure
- Log out from shared computers
- Report suspicious activity
- Use strong, unique passwords
- Follow Django security guidelines
- Validate all user inputs
- Use HTTPS in production
- Keep dependencies updated
- Implement proper error handling
- Use environment variables for secrets
- Vulnerability Assessment: Within 24 hours
- Patch Development: 1-7 days depending on severity
- Testing: Comprehensive security testing
- Release: Coordinated disclosure with patch
- Communication: Security advisory to users
We appreciate security researchers and users who help keep PlayBharat secure. Responsible disclosure will be acknowledged in:
- Security advisories
- Release notes
- Hall of fame (coming soon)
- Django Security Documentation
- OWASP Web Application Security Testing Guide
- Python Security Best Practices
Remember: Please do not disclose security vulnerabilities publicly until we have had a chance to address them.