Skip to content

Security: clipinfit/convex-teams

SECURITY.md

Security policy

Report vulnerabilities through GitHub private vulnerability reporting. Private reporting is enabled for this repository. Do not post working exploits, credentials, invitation tokens, or personal data in a public issue.

Include the package and Convex versions, the affected operation, expected and observed behavior, and a minimal reproduction with synthetic identities. Describe whether the issue crosses a team boundary or restores removed access.

During prerelease development, fixes target the latest release candidate. After the first stable release, fixes target the latest stable version. Older prereleases receive no separate maintenance commitment.

Host applications must authenticate callers, derive trusted user IDs and verified email addresses, and authorize product resources. Component installation does not secure host tables or signed media URLs.

There aren't any published security advisories