Security fixes are only released for the latest version of Metan Mobile. Please make sure you are on the latest version from Google Play or the App Store before reporting an issue.
| Platform | Version | Supported |
|---|---|---|
| Android | 2.3.x | ✅ |
| Android | < 2.3 | ❌ |
| iOS | 1.0.x | ✅ |
Please do not report security vulnerabilities through public GitHub issues, discussions or pull requests.
Report them privately instead:
-
through GitHub private vulnerability reporting, or
-
by email to [email protected] with the subject
[Security] Metan Mobile. Please include: -
the affected platform (Android or iOS) and app version,
-
a description of the issue and its possible impact,
-
steps to reproduce, a proof of concept, or both,
-
any suggested fix, if you have one.
- Acknowledgement within 3 working days.
- First assessment within 7 days, including whether the report is accepted and how severe it is.
- Status updates at least once a week until the issue is resolved.
- If accepted: a fix is released in the next app update. Critical issues get a hotfix. With your permission, you will be credited in the release notes.
- If declined: you will get an explanation of why it is not considered a vulnerability.
Please give us reasonable time to release a fix before you disclose the issue publicly.
In scope:
- the Metan Mobile Android and iOS apps from this repository,
- the Metan Mobile API that the apps use for data.
Out of scope:
- third-party services and SDKs (Firebase, Google Maps, AdMob, Yandex Mobile Ads). Please report issues in those directly to their vendors.
- the content and availability of the source data, which comes from open sources.