Skip to content

Security: CourtHive/TMX

Security

SECURITY.md

Security Policy

This policy applies to CourtHive repositories that do not publish a security policy of their own.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability.

Email charles@courthive.com with:

  • which repository and version it affects,
  • a reproduction — the smallest input or sequence that demonstrates it,
  • what an attacker gets out of it.

You can expect an acknowledgement within a few days. If the report is confirmed, you will be told when a fix is released, and credited in the release notes unless you would rather not be.

If you are not sure which repository owns the issue, send it anyway and it will be routed.

Supported versions

Security fixes are released against the latest published minor of a package's current major. Older majors are not patched.

What is worth reporting

CourtHive software handles tournament records, participant data and competition results. The issues that matter most:

  • Untrusted input handled unsafely — a record, policy definition or scoring string that causes unbounded recursion, catastrophic backtracking, prototype pollution or a crash.
  • Data exposure across boundaries — participant personal information, unpublished results, or another organization's tournament data reaching a caller that should not receive it. Publishing and embargo behaviour is the highest-consequence surface in this ecosystem.
  • Authentication or authorization defects in the server and application repositories.
  • Supply-chain problems — anything unexpected in a published npm package.

There aren't any published security advisories