Skip to content

Security: jcodeforge/invoice4j

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest released version of invoice4j is supported and receive security fixes.


Reporting a Vulnerability

If you discover a security vulnerability in invoice4j, please do not open a public GitHub issue.

Instead, report it privately by email:

Email: [email protected]

Please include as much information as possible:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected version(s)
  • Proof of concept (if available)
  • Suggested mitigation (optional)

Response Process

After receiving a report, we will:

  1. Acknowledge receipt
  2. Investigate the reported issue
  3. Develop and test a fix if necessary
  4. Publish a patched release.
  5. Credit the reporter (if desired)

Scope

Security reports may include issues such as:

  • XML parsing vulnerabilities
  • XXE (XML External Entity) attacks
  • XML signature verification issues
  • Denial of Service (DoS)
  • Dependency vulnerabilities
  • Data integrity issues
  • Injection vulnerabilities

Disclosure Policy

Please allow reasonable time for the issue to be investigated and fixed before publicly disclosing any vulnerability.

We appreciate responsible disclosure and will work with reporters to resolve issues as quickly as possible.

There aren't any published security advisories