Thank you for your interest in the security of my GitHub project! This policy describes how to report security vulnerabilities and what to expect when doing so.
If you find a potential security vulnerability in my project, please follow these steps:
-
Send a private email or create an issue: create a public issue in the repository or send an email to jean.albuquerque@sptech.school with the details of the vulnerability.
-
Include Details: Provide as much detail as possible about the vulnerability, including:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Possible solutions or mitigations, if you have any
-
Response Time: I commit to responding to your message within some days.
-
Assessment: I will assess the reported vulnerability to understand its severity and impact.
-
Fix: Depending on the severity, I will work on a fix as quickly as possible. For critical vulnerabilities, a fix will be prioritized.
-
Communication: After resolving the vulnerability, I will notify the reporter and release an update in the repository. If applicable, a security advisory will be issued.
-
Credit: I will give credit to the reporter for discovering the vulnerability unless the reporter prefers to remain anonymous.
This security policy applies to all parts of this project, including:
- Source code
- Included dependencies and libraries
- Deployment configurations and example settings
Thank you for helping to keep this project secure. Your contribution is valuable and helps to ensure the security and integrity of my project and my learning.
If you have any questions about this policy or any other security-related concerns, feel free to contact me