Skip to content

Security: tina4stack/tina4-documentation

SECURITY.md

Security Policy

Supported versions

This repository is the source of https://tina4.com. The live site and the installer scripts it serves (install.sh, install.ps1, install-skills.*) are supported. Report problems with the framework code in the framework's own repository; if you are unsure which, report here and we will move it.

Reporting a vulnerability

Please do not open a public issue, pull request or discussion for a security problem.

Report it privately, using either of these:

  1. GitHub private vulnerability reporting (preferred): open the repository's Security tab and choose Report a vulnerability. You and the maintainers get a private advisory to work in.
  2. Email: [email protected], with SECURITY in the subject line.

The full policy, including our safe-harbour commitment for good-faith research, is at https://tina4.com/general/security-research.html.

Please include:

  • the affected package and version (or commit)
  • the language/framework and database engine, where relevant
  • steps to reproduce, or a proof of concept
  • the impact you believe it has

What happens next

Step Target
Acknowledge your report 3 business days
Triage and severity (CVSS v3.1) 10 business days
Fix released: Critical / High 30 days from triage
Fix released: Medium / Low next scheduled release, at most 90 days
Public advisory (GitHub Security Advisory, CVE where applicable) when the fix ships

Tina4 ships one framework in four languages (Python, PHP, Ruby, Node.js). A vulnerability found in one is checked in all four, and fixed in every affected framework in the same release.

We practise coordinated disclosure. Please give us the time above before disclosing publicly; we will agree a date with you and credit you in the advisory unless you ask us not to.

Scope

In scope: this repository's code, its published packages, and release artefacts built from it.

Out of scope: applications built with Tina4 (report those to their owners), and features that are only enabled in development mode (TINA4_DEBUG=true) when the report depends on exposing a development server to an untrusted network. Reports that show a development feature can be reached from a normal production configuration are in scope.

There aren't any published security advisories