We release patches for security vulnerabilities for the following versions:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
We take the security of SCV seriously. If you believe you have found a security vulnerability, please report it to us as described below.
- Report security vulnerabilities privately - Do not create public GitHub issues for security vulnerabilities
- Provide detailed reports - Include steps to reproduce, potential impact, and suggested fixes if possible
- Give us reasonable time - Allow us time to investigate and address the issue before public disclosure
- Don't exploit vulnerabilities - Beyond what is necessary to demonstrate the issue
- Don't access other users' data - Even for testing purposes
- Don't perform attacks - That could harm the reliability or integrity of our services
- Go to the Security tab of this repository
- Click "Report a vulnerability"
- Fill out the vulnerability report form
If you prefer email, contact the maintainers directly through their GitHub profiles.
Please include the following information in your report:
- Type of vulnerability (e.g., SQL injection, XSS, authentication bypass)
- Location - Full paths of source file(s) related to the issue
- Steps to reproduce - A step-by-step description of how to reproduce the issue
- Proof of concept - Code or screenshots demonstrating the vulnerability
- Impact - What an attacker could achieve with this vulnerability
- Suggested fix - If you have recommendations for how to fix the issue
- Initial Response: Within 48 hours of receiving your report
- Status Update: Within 7 days with our assessment
- Resolution Timeline: Depends on severity, typically:
- Critical: 24-48 hours
- High: 7 days
- Medium: 30 days
- Low: 90 days
If you're self-hosting SCV, please follow these security guidelines:
- Never commit
.envfiles to version control - Use strong secrets for
BETTER_AUTH_SECRET(32+ random characters) - Rotate secrets periodically
- Use different credentials for development and production
- Use strong passwords for PostgreSQL
- Enable SSL for database connections in production
- Restrict network access to your database
- Regular backups with encryption
- Enable OAuth providers (GitHub, Google) for secure authentication
- Use HTTPS in production for
BETTER_AUTH_URL - Review session settings for your security requirements
- Keep dependencies updated - Run
npm auditregularly - Use HTTPS - Never deploy without TLS
- Set security headers - CSP, HSTS, etc.
- Regular updates - Keep Node.js and all dependencies current
- Don't run as root - Our Dockerfile uses a non-root user
- Use secrets management - Don't pass secrets via environment variables in production
- Scan images - Use tools like Trivy to scan for vulnerabilities
- Keep base images updated - Regularly rebuild with latest base images
SCV stores the following sensitive data:
- User account information (email, name)
- Wedding guest information (names, emails, addresses)
- RSVP responses
- Better Auth - Self-hosted authentication (no external auth service)
- AWS S3 (optional) - For image uploads, ensure proper bucket policies
- OAuth Providers (optional) - GitHub, Google authentication
We appreciate the security research community and will acknowledge researchers who responsibly disclose vulnerabilities (unless they prefer to remain anonymous).
Thank you for helping keep SCV and its users safe!