Skip to content

Security: Abhishekucs/feedback.dev

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use GitHub's private vulnerability reporting for this repository. Include as much of the following as you can:

  • A description of the issue and its impact
  • Steps to reproduce
  • Affected components (apps/api, apps/web, packages/widget, etc.)

You should receive a response within a few days. Please give us a reasonable window to ship a fix before any public disclosure.

Scope notes

  • Widget API keys (fbk_...) are public by design — they are embedded in script tags on third-party websites and only allow submitting feedback and reading the form config for that project. Exposure of a widget key is not a vulnerability by itself.
  • Reports about missing rate limits, auth bypasses on the dashboard, or cross-project data access are very much in scope.

There aren't any published security advisories