Skip to content

Security: alihdrndm/blockpace

SECURITY.md

Security policy

Reporting a vulnerability

Please report security problems privately through GitHub: Security → Report a vulnerability.

Do not open a public issue for a vulnerability. Include what you found, how to reproduce it, and which version or commit you tested. You will get an answer within 7 days. A fix and a public advisory follow once the problem is confirmed.

Supported versions

Only the latest commit on main receives security fixes.

What data blockpace handles

  • Hotel room-block contracts: block and hotel names, nightly room counts, room rates and attrition terms.
  • Pickup snapshots: how many rooms were reserved per night.
  • Webhook endpoint URLs and their signing secrets. Secrets are generated by the server, shown once at creation, and never returned again.

blockpace stores no guest names, no contact details and no payment data. One API key (API_KEY) protects every /v1 endpoint.

Known limitations

  • DNS rebinding: webhook URLs are checked when an endpoint is created and again before every delivery. A URL must use https and must not resolve to a loopback, private, link-local, carrier-grade NAT or unspecified address. The check does not defend against DNS rebinding: a host can resolve to a public address during the check and to a private one when the request is sent.
  • ALLOW_PRIVATE_WEBHOOK_TARGETS=true turns that check off for local development. Never set it in production.

How the repository is protected

  • main can only change through pull requests that pass CI (verify, e2e) and CodeQL.
  • Secret scanning with push protection, Dependabot alerts and security updates, and dependency review on pull requests are enabled.
  • GitHub Actions are pinned to commit SHAs and run with read-only permissions by default.

There aren't any published security advisories