Masterplan Optimiser

Masterplan Optimiser

Open-source scheduling platform

Public information

Security

How to report a vulnerability safely and which releases receive security fixes.

Do not send credentials, recovery material, personal data, production databases, or private incident evidence through a public issue.

Supported versions

Only the latest signed production release receives security fixes. Test deployments are intentionally unsigned and must not be treated as a production release.

Reporting a vulnerability

Do not open a public issue containing exploit details, personal data, credentials, server addresses or recovery material. Use GitHub's private vulnerability reporting for this repository. If that feature is unavailable, contact the maintainer privately before sharing technical details.

Include the affected version, deployment topology, reproducible impact and the least sensitive evidence needed to investigate. Never send a production database or recovery snapshot.

Deployment responsibility

Masterplan Optimiser is self-hosted. Each operator controls its VPS, DNS, email and backup providers and is responsible for timely updates, account security and an appropriate incident response. The project has no central telemetry and cannot see a deployment's operational state.

See the security architecture, incident-response guide and supported-versions policy.