Skip to content
This repository has been archived by the owner on Sep 22, 2023. It is now read-only.

Security: shravzzv/Archived-Personal-Website

Security

SECURITY.md

Security Policy

Supported Versions

Please refer to this section to understand which versions of the project are currently supported with security updates.

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability within the project's GitHub repository, we encourage you to report it to us promptly. This will help ensure the security and integrity of the project and its users. We appreciate your efforts in disclosing the issue responsibly and will make every effort to address it in a timely manner.

To report a vulnerability, please follow these steps:

  1. Submit a detailed report via email to [shravzzv@outlook.com]. Include the following information:

    • A clear description of the vulnerability, including the steps to reproduce it.
    • Any relevant technical details, such as affected versions or components.
    • Proof-of-concept code or any other supporting material that demonstrates the vulnerability, if applicable.
  2. Our security team will acknowledge your report within [48 hours] and begin investigating the issue.

  3. We will maintain regular communication with you to provide updates on the progress of the investigation. You can expect an update within [5 business days] regarding the initial assessment of the reported vulnerability.

  4. Once the vulnerability has been validated and resolved, we will share the details of the fix and coordinate with you on the appropriate disclosure timeline.

Guidelines for Responsible Disclosure

To ensure the safety of our users and the project, we kindly request that you adhere to the following guidelines during the disclosure process:

  1. Act in good faith: Make a genuine effort to avoid privacy violations, destruction of data, and disruption of services during your security research.

  2. Avoid public disclosure before resolution: Please refrain from publicly disclosing the vulnerability before we have had sufficient time to address it. We will work diligently to resolve the issue as quickly as possible.

  3. Respect user privacy: Do not access, modify, or exfiltrate user data without explicit permission.

  4. Provide adequate information: When reporting the vulnerability, please include all relevant details to help us understand and reproduce the issue.

  5. Do not exploit or further damage the system: Once you have reported a vulnerability, please do not attempt to exploit it further or conduct additional attacks on the system.

  6. Follow responsible disclosure practices: Coordinate with us to establish an appropriate disclosure timeline and plan to ensure the security of all users.

Recognition and Acknowledgment

We value the contributions of security researchers in improving the security of the project. If you report a vulnerability that leads to a valid fix, we will gladly recognize your contribution. Depending on the severity and impact of the vulnerability, we may acknowledge your effort publicly or include you in our private hall of fame. However, we will respect your wishes for anonymity if you prefer not to be publicly acknowledged.

Thank you for helping us maintain the security and integrity of our project. Your assistance is greatly appreciated.

There aren’t any published security advisories