The TarkovTracker-org organization takes the security of our software, infrastructure, and user data seriously. This document outlines our vulnerability disclosure process, response commitments, and project scope across all repositories under the tarkovtracker-org organization.
Precedence Note: This policy acts as the organization-wide default. Individual repositories (such as the flagship
TarkovTrackerweb app) may publish their ownSECURITY.mddetailing repository-specific scopes, endpoints, or infrastructure. When present, the repository-level policy takes precedence.
Unless explicitly stated otherwise in an individual repository:
- Web applications & services (e.g., TarkovTracker, Cloudflare Workers, Supabase functions): Only the latest deployment of the default branch (
main) is actively supported with security fixes. - Desktop utilities & bots (e.g., RatScanner, TarkovMonitor, TrackerBot): Only the latest tagged release and current
mainbranch receive security patches. - Older versions, superseded tags, and archived repositories are not maintained and will not receive backported security patches.
Please DO NOT report security vulnerabilities through public GitHub issues, pull requests, public Discord messages, or social media.
To protect users and their data, report security issues through either of the following private channels:
Submit a private advisory directly through GitHub on the affected repository:
- Go to the repository's Security tab.
- Click Report a vulnerability (or use the direct URL pattern:
https://github.com/tarkovtracker-org/<repo-name>/security/advisories/new). - This opens a draft security advisory that only you (the reporter), repository maintainers, and any collaborators they add can view.
If GitHub Private Vulnerability Reporting is unavailable, send an email to:
- ✉️ mailto:security@tarkovtracker.org
- Subject Line Format:
[SECURITY REPORT] <Repository/Component> - <Brief Description>
To help us evaluate and address your finding promptly, please provide:
- Affected Component: Repository name, URL, service, file path, or API endpoint.
- Vulnerability Type: e.g., Cross-Site Scripting (XSS), SQL / RLS bypass, Broken Authentication, Sensitive Data Exposure, Remote Code Execution.
- Step-by-step Reproduction: Clear, repeatable steps demonstrating the issue.
- Proof of Concept (PoC): Minimal, benign reproduction script, screenshot, or HTTP request payload.
- Impact Assessment: Explanation of what an attacker could realistically achieve by exploiting the vulnerability.
- Suggested Remediation: Proposed code fix or configuration change, if known.
TarkovTracker-org is maintained by volunteers. When you disclose a vulnerability responsibly, we aim to meet the following targets:
- Acknowledgment: Within 72 hours of receiving your report.
- Initial Triage & Assessment: Within 7 days, confirming reproducibility, severity, and planned remediation.
- Fix & Deployment: We strive to release fixes promptly based on CVSS severity:
- Critical / High: Within 7 to 14 days of triage.
- Medium / Low: Next scheduled release or deployment cycle.
- Coordinated Disclosure: We work collaboratively with reporters on disclosure timing. We request that you refrain from public disclosure until an official fix is deployed.
The following areas and testing methods are strictly outside our security scope:
- Denial of Service (DoS/DDoS) attacks against production infrastructure or live APIs.
- Automated vulnerability scanner dumps without manual verification and reproducible proof of impact.
- Social engineering, phishing, or physical attacks against maintainers or contributors.
- Third-party upstream platform issues (e.g., Supabase, Cloudflare, Discord, GitHub, or Battlestate Games services) that do not originate from our configuration or codebase.
- Data correctness issues in tarkov.dev or tarkov-data-overlay (report these via normal issue trackers).
- Credit: With your permission, we will credit security researchers in release notes and security advisories. If you prefer to remain anonymous, let us know and we will respect your privacy.
- Safe Harbor: We will not pursue legal action against individuals who discover and report vulnerabilities in good faith according to this policy, avoid data destruction or privacy violation, and provide reasonable time for remediation prior to public disclosure.