If you discover a security vulnerability in DIVE Tools, please report it responsibly.
- Email: mateo@callec.net
- Include a clear description of the issue, steps to reproduce, and any relevant logs or screenshots.
- Please avoid public disclosure until the issue has been addressed.
- 1.0.0 – initial release
Security fixes will be backported to all supported versions as necessary.
- Keep dependencies up to date.
- Run the API behind HTTPS.
- Use a strong
SECRET_KEYin.env. - Validate URLs carefully before processing.
- We aim to acknowledge security reports within 48 hours.
- Critical vulnerabilities will be addressed promptly, with patches released as needed.