If you discover a security vulnerability, please report it privately: do not post it publicly. Email the maintainer at contact@trackmyprotein.se with steps to reproduce, the affected area, and any proof-of-concept. We will arrange a secure channel if needed.
The hosted application always runs the latest version. Security fixes are applied on a rolling basis; older snapshots are not maintained.
In scope: the application itself and its default deployment configuration. Out of scope: vulnerabilities in third-party dependencies that are already publicly known (these are tracked via automated dependency scanning), issues requiring a compromised host or physical access, and misconfigurations in a self-hosted deployment that deviate from the documented defaults.
A Software Bill of Materials (SBOM) is generated on every build, dependencies and the container image are monitored by Dependabot, and Trivy scans the dependencies and image on every build and weekly. This complements the app's audit logging and reflects our move toward alignment with the EU Cyber Resilience Act (CRA) vulnerability-handling expectations.
For any security-related questions: contact@trackmyprotein.se