Security policy

Good-faith vulnerability reports are welcome and appreciated.

Reporting a vulnerability

Please do not open a public issue for a security problem. Use GitHub's private vulnerability reporting on the Security tab of the repository, which reaches the maintainer only, or email help@getstoop.org.

Include what you can: the version (stoop --version, or Server admin → Server), how the instance is exposed, and steps to reproduce. A proof of concept against your own instance is welcome; please do not test against instances you do not run. Fixes may ship as a patch release with a note crediting the reporter, unless they prefer otherwise.

Supported versions

The newest release. Stoop upgrades in place from the release before it, so staying current is the supported path. The newest minor is patched; older minors are not.

Scope

In scope: the Stoop server and web app, the desktop app, the release images, and the compose and configuration examples that ship with a release.

Out of scope: LiveKit, Postgres, Cloudflare, Tailscale and other software Stoop is deployed alongside (report to them directly), and findings that require the operator to have ignored the self-hosting guide, such as exposing the server over plain HTTP to the internet.