Skip to content

Security: chrisjohnleah/sage-business-cloud-accounting-api

SECURITY.md

Security Policy

Supported versions

This project is in early development. Security fixes are applied to the latest release on the main branch.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, email christopher.leah@happywebs.co.uk with:

  • a description of the vulnerability and its impact,
  • steps to reproduce (a proof of concept if possible),
  • any suggested remediation.

You'll receive an acknowledgement as soon as possible, and a fix or mitigation plan once the report has been triaged. Please give a reasonable window to address the issue before any public disclosure.

Scope notes

This SDK handles OAuth credentials and access/refresh tokens. When reporting, please be mindful of anything touching token storage, the OAuth flow, or the handling of the X-Business header.

There aren't any published security advisories