Skip to content

Security: Saumya-b10/MedInternia

Security

SECURITY.md

Security Policy

MedInternia is a healthcare-focused learning and collaboration platform, so security reports should be handled carefully and privately.

Supported Versions

Security fixes are currently accepted for the main branch.

Reporting a Vulnerability

Please do not open a public issue for sensitive vulnerabilities.

To report a security concern:

  1. Contact the maintainers listed in README.md.
  2. Include the affected area, reproduction steps, expected impact, and any safe proof of concept.
  3. Avoid sharing real patient, student, or private medical data in reports.

Maintainers should acknowledge valid reports as soon as possible and coordinate a fix before public disclosure.

Scope

Examples of security issues include:

  • Authentication or authorization bypass
  • Exposure of private user or medical data
  • Injection vulnerabilities
  • Unsafe file upload behavior
  • Leaked secrets or insecure default configuration

There aren't any published security advisories