Skip to content

Security: hmcts/appreg-frontend

Security

SECURITY.md

Security policy

Reporting a vulnerability

This repository is public, but the service it supports is intended for internal HMCTS and justice users.

If you discover a security vulnerability in this repository or the service, do not report it in a public GitHub issue, pull request, comment or discussion.

Report vulnerabilities using the HMCTS Vulnerability Disclosure Policy:

https://www.gov.uk/guidance/hmcts-vulnerability-disclosure-policy

When reporting a vulnerability, please include:

  • a summary of the issue
  • steps to reproduce
  • affected page, route, component or service
  • potential impact
  • any suggested mitigation, if known

Responsible disclosure

Please allow time for the issue to be investigated and fixed before making any public disclosure.

Do not include secrets, credentials, personal data or exploit details in public channels.

Scope

This policy applies to all code and configuration in this repository, including:

  • application code
  • frontend assets and routing
  • CI/CD and deployment configuration
  • third-party packages and dependencies

Supported versions

Security updates are applied to supported versions of the service.

Maintainers

Repository maintainers will triage reported vulnerabilities and work with the appropriate HMCTS and platform security teams where needed.

There aren't any published security advisories