Skip to content
This repository was archived by the owner on Sep 11, 2026. It is now read-only.

Security: SpringTree/react-native-amplitude-sdk

Security

SECURITY.md

Security policy

SpringTree takes security reports seriously. Thank you for taking the time to disclose an issue to us responsibly.

Reporting a vulnerability

Report vulnerabilities by email to security@springtree.nl.

Please do not open a public issue, pull request or discussion for a security problem. A public report exposes the issue to everyone before a fix exists.

What to include

The more of this we receive up front, the faster we can act:

  • The affected repository, application URL or package name.
  • The version, release or commit hash you tested against.
  • Step-by-step instructions to reproduce the issue.
  • The impact you believe it has — what an attacker could reach or change.
  • Any proof-of-concept code, logs or screenshots.
  • How we can reach you for follow-up questions.

What to expect

  • We acknowledge your report within 5 business days.
  • We keep you informed of our assessment and of the progress towards a fix.
  • We let you know when the issue is resolved, and we are happy to credit you in the release notes unless you prefer to stay anonymous.

Scope

This policy covers software developed and maintained by SpringTree.

SpringTree also builds and operates software on behalf of clients. If your report concerns a system that a client owns, we forward it to that client and tell you that we did. The client's own disclosure process then applies, and the timelines above may not.

Coordinated disclosure

Please give us a reasonable opportunity to fix the issue before you publish any details. We will agree a disclosure moment with you, and with the client where a client system is involved.

While investigating, please stay within these boundaries:

  • Do not access, modify or delete data that is not your own.
  • Do not degrade the availability of our services or those of our clients — no denial-of-service testing, no automated high-volume scanning.
  • Do not use social engineering, phishing or physical intrusion.

SpringTree does not operate a bug bounty programme; we cannot offer a financial reward for reports.

There aren't any published security advisories