Skip to content

Security: SAP-samples/fiori-tools-samples

Security

.github/SECURITY.md

Security Policy

Reporting Security Issues

Do not report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability, please report it to SAP:

Include the following information:

  • Type of issue (e.g., XSS, SQL injection, code execution)
  • Full paths of affected source files
  • Location of the affected code (tag/branch/commit)
  • Step-by-step instructions to reproduce
  • Proof-of-concept or exploit code (if possible)
  • Impact assessment

Response Process

  1. You will receive acknowledgment within 3 business days
  2. SAP will investigate and provide updates
  3. Once resolved, we will coordinate disclosure timing with you

Supported Versions

This is a sample repository. Security updates apply to the latest code on the main branch only.

Security Best Practices

These samples are for learning purposes. When using in production:

  • Update all dependencies regularly
  • Review and test all code thoroughly
  • Follow SAP security guidelines
  • Enable appropriate authentication and authorization
  • Validate all inputs and sanitize outputs

Disclosure Policy

SAP follows coordinated vulnerability disclosure principles. We request reasonable time to address issues before public disclosure.

For more information, visit SAP Trust Center.

There aren’t any published security advisories