Please report security problems privately through GitHub: Security → Report a vulnerability.
Do not open a public issue for a vulnerability. Include what you found, how to reproduce it, and which version or commit you tested. You will get an answer within 7 days. A fix and a public advisory follow once the problem is confirmed.
Only the latest commit on main receives security fixes.
- Hotel room-block contracts: block and hotel names, nightly room counts, room rates and attrition terms.
- Pickup snapshots: how many rooms were reserved per night.
- Webhook endpoint URLs and their signing secrets. Secrets are generated by the server, shown once at creation, and never returned again.
blockpace stores no guest names, no contact details and no payment data. One API key (API_KEY) protects every /v1 endpoint.
- DNS rebinding: webhook URLs are checked when an endpoint is created and again before every delivery. A URL must use
httpsand must not resolve to a loopback, private, link-local, carrier-grade NAT or unspecified address. The check does not defend against DNS rebinding: a host can resolve to a public address during the check and to a private one when the request is sent. ALLOW_PRIVATE_WEBHOOK_TARGETS=trueturns that check off for local development. Never set it in production.
maincan only change through pull requests that pass CI (verify,e2e) and CodeQL.- Secret scanning with push protection, Dependabot alerts and security updates, and dependency review on pull requests are enabled.
- GitHub Actions are pinned to commit SHAs and run with read-only permissions by default.