Skip to content

Security: SloppyBobbert/Dosey

SECURITY.md

Security Policy

Dosey is an unsupported early prototype, not a medical-grade device. Reports help improve the project, but no response or remediation timeline is promised.

Reporting a vulnerability

Use GitHub's Report a vulnerability option for this repository when it is available. Include a minimal reproduction, affected revision, impact, and any safe mitigation you found.

If private vulnerability reporting is unavailable, do not publish sensitive details in an issue. Open a minimal public issue requesting a private reporting channel without describing the vulnerability, or use a repository maintainer's GitHub contact option if one is published. Do not invent or guess an email address.

Report suspected problems involving:

  • exposure of local medication data, backup data, or account information;
  • leaked credentials, tokens, API keys, or other secrets;
  • pairing, authorization, or authentication flaws; and
  • unintended movement, jams, unsafe controller behavior, or other physical safety concerns.

Do not include real medication, patient, caregiver, account, or secret data in a report. Do not test a report with prescription medication. Use fake pills, candy, beads, dry beans, or vitamins for any supervised prototype test.

There aren't any published security advisories