Skip to content

Security: Alexander1752/ss-web

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Do not at first open public issues for security vulnerabilities.


What to Include in a Report

To help us triage and resolve the issue quickly, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact and attack scenarios
  • Any proof-of-concept code or screenshots (if applicable)
  • Suggested fixes (optional, but appreciated)

Scope

This project allows users to self-host a web interface for viewing camera feeds from Android devices and ESP32-based cameras. Security considerations include, but are not limited to:

  • Unauthorized access to camera feeds
  • Weak authentication or misconfiguration
  • Exposure of video streams over insecure networks
  • API or endpoint vulnerabilities
  • Device-level security risks (Android / ESP32 firmware interactions)

Disclosure Policy

  • We aim to acknowledge receipt of vulnerability reports within 48 hours
  • We will provide an estimated timeline for a fix after initial assessment
  • Once resolved, we may credit you in the release notes (unless you prefer to remain anonymous)

Security Updates

Security fixes will be released as soon as possible and documented in:

  • Release notes
  • Commit history

Disclaimer

This is a self-hosted project. The maintainers are not responsible for:

  • Misconfiguration by users
  • Insecure deployment environments
  • Compromised devices (Android or ESP32)
  • Data exposure due to improper security practices

Thank you for helping keep this project and its users safe.

There aren't any published security advisories