Files
picpeak/.github/ISSUE_TEMPLATE/security_vulnerability.md
T
Paul Nothaft 0205c7dcce chore: migrate Docker registry + GitHub URLs to PicPeak org
Repo transferred from the-luap/picpeak → PicPeak/picpeak. Docker images
publish to ghcr.io/picpeak/picpeak/{backend,frontend} (lowercase, per the
GHCR canonical form computed by docker-build.yml's `${GITHUB_REPOSITORY,,}`).

Sweep covers:
- docker-compose.production.yml + Dockerfiles → new image registry path
- README, CONTRIBUTING, SECURITY, SIMPLE_SETUP, scripts/picpeak-setup.sh
  → new GitHub URLs
- Update-check / release-notes services (updateCheckService,
  environmentService, updateNotificationService, adminSystem,
  UpdateNotification, githubReleaseUrl) → GitHub API + tag URLs use the
  canonical PicPeak/picpeak path
- Issue templates + README-DOCKER + workflow README → updated package URLs
- One commit-context comment in migrations/090 + customerAccountsService

CHANGELOG.md is intentionally untouched (historical release entries are
immutable; GitHub auto-redirects the old URLs indefinitely).
CLAUDE.md keeps the bare `(the-luap)` reference — that's the maintainer's
personal handle, not a repo URL.

22 files, 48/48 line swaps (every change is a 1:1 URL replacement).
2026-06-29 20:20:13 +02:00

976 B

name, about, title, labels, assignees
name about title labels assignees
Security Vulnerability Report security issues privately [SECURITY] security

⚠️ IMPORTANT: For serious security vulnerabilities, please DO NOT create a public issue.

Instead, please use GitHub Private Vulnerability Reporting or email info@picpeak.app with the details.

For minor security improvements or questions, you can use this template:

Type of Security Issue

  • Authentication/Authorization
  • Data Exposure
  • Input Validation
  • Configuration Issue
  • Dependency Vulnerability
  • Other: ___________

Description Brief description of the security concern.

Impact What could an attacker potentially do?

Steps to Reproduce If applicable, how can this be reproduced?

Suggested Fix If you have ideas on how to fix this issue.

References Any relevant security advisories, CVEs, or documentation.