Skip to content

Security: ArsalanRC/integration-patterns

SECURITY.md

Security policy

English · Deutsch


English

Reporting a vulnerability

Please do not open a public issue for a security problem.

Use GitHub's private vulnerability reporting instead: go to the repository's Security tab and choose Report a vulnerability. That opens a private thread visible only to me, and it works without either of us publishing an email address.

If that is unavailable for some reason, reach me through LinkedIn.

What to expect

First reply Within 7 days
Assessment Within 14 days
Fix or a stated reason not to Within 30 days for anything exploitable

These are personal projects maintained in evenings and weekends, so I would rather promise a timeline I can keep than a fast one I cannot.

Scope

These are libraries and static sites. There is no server holding your data and no account to compromise, so the realistic risk surface is narrower than for a hosted product. Things genuinely worth reporting:

  • Input that causes a parser to hang, crash, or consume unbounded memory
  • A dependency with a known advisory that one of these repos pulls in
  • Anything in the published examples that would be unsafe if copied into production, which for the integration repos is the one that would bother me most
  • Credentials or personal data committed by accident

Not in scope

  • Missing hardening headers on a GitHub Pages site I do not control the serving of
  • Results from an automated scanner with no demonstrated impact
  • Anything requiring an attacker to already control the victim's machine

Credit

Tell me how you want to be credited and I will do it. If you would rather stay anonymous, that is fine too.


Deutsch

Sicherheitslücke melden

Bitte kein öffentliches Issue für ein Sicherheitsproblem.

Nutze stattdessen GitHubs private Meldefunktion: im Repository auf den Reiter Security und dort Report a vulnerability. Das öffnet einen privaten Thread, den nur ich sehe, und funktioniert, ohne dass einer von uns eine E-Mail-Adresse veröffentlicht.

Falls das nicht geht, erreichst du mich über LinkedIn.

Was du erwarten kannst

Erste Rückmeldung Innerhalb von 7 Tagen
Einschätzung Innerhalb von 14 Tagen
Fix oder eine begründete Ablehnung Innerhalb von 30 Tagen, sofern ausnutzbar

Das sind private Projekte, gepflegt an Abenden und Wochenenden. Mir ist eine Frist lieber, die ich halte, als eine schnelle, die ich reiße.

Was in den Rahmen fällt

Es handelt sich um Bibliotheken und statische Seiten. Es gibt keinen Server mit deinen Daten und keinen Account zum Übernehmen, die realistische Angriffsfläche ist also kleiner als bei einem gehosteten Produkt. Wirklich meldenswert:

  • Eingaben, bei denen ein Parser hängt, abstürzt oder unbegrenzt Speicher frisst
  • Eine Abhängigkeit mit bekannter Advisory, die eines dieser Repos hereinzieht
  • Alles in den veröffentlichten Beispielen, das unsicher wäre, wenn man es in Produktion kopiert. Bei den Integrations-Repos wäre mir genau das am unangenehmsten
  • Versehentlich committete Zugangsdaten oder personenbezogene Daten

Was nicht in den Rahmen fällt

  • Fehlende Security-Header auf einer GitHub-Pages-Seite, deren Auslieferung ich nicht steuere
  • Scanner-Ergebnisse ohne belegte Auswirkung
  • Alles, wofür ein Angreifer bereits den Rechner des Opfers kontrollieren muss

Nennung

Sag mir, wie du genannt werden möchtest, dann mache ich das. Anonym ist genauso in Ordnung.

There aren't any published security advisories