Skip to content

Security: telekom/whereabouts

SECURITY.md

SPDX-FileCopyrightText: 2026 Deutsche Telekom AG

SPDX-License-Identifier: CC-BY-4.0

Security Policy

Supported Versions

Security fixes are provided for the current main branch and for actively maintained release tags published by this repository.

Reporting a Vulnerability

Please report suspected vulnerabilities privately through GitHub Security Advisories for this repository:

https://github.com/telekom/whereabouts/security/advisories/new

If GitHub Security Advisories are not available to you, contact the maintainers through the Deutsche Telekom T-CaaS team and include enough detail to reproduce and assess the issue.

What to Include

  • Affected component, version, branch, or commit.
  • Steps to reproduce or a proof of concept.
  • Impact assessment and any known mitigations.
  • Whether the issue is already public.

Response Expectations

The maintainers triage private vulnerability reports as soon as practical. Confirmed vulnerabilities are handled privately until a fix, mitigation, or advisory is ready. Public disclosure is coordinated with the reporter when possible.

There aren't any published security advisories