Security Policy
Information regarding responsible vulnerability disclosure, supported versions, and security reporting procedures for this project.
Supported Versions
This project is maintained on a rolling basis.
- Latest Version — Supported
- Older Versions — Not Supported
Reporting a Vulnerability
If you discover a security vulnerability affecting this project, please report it responsibly.
A report should include:
- Description of the vulnerability
- Steps required to reproduce the issue
- Potential impact
- Proof of concept, if applicable
- Suggested remediation (optional)
Please do not publicly disclose vulnerabilities until they have been reviewed and assessed.
Scope
This policy applies to:
- Website source code
- Client-side JavaScript
- Configuration files
- GitHub Pages deployment
Examples of relevant issues include:
- Cross-site scripting (XSS)
- Content injection vulnerabilities
- Security misconfigurations
- Dependency vulnerabilities
- Information disclosure caused by project code
Out of Scope
The following generally fall outside the scope of this policy:
- Issues originating solely from third-party providers
- Social engineering attempts
- Denial-of-service testing
- Automated spam submissions
- Physical access attacks
- Browser-specific issues unrelated to project code
Third-Party Services
This website may utilize third-party APIs, embedded content, hosting infrastructure, comment platforms, analytics services, and external resources.
Security issues originating from third-party providers should be reported directly to the maintainers of those services.
Response Process
Vulnerability reports will be reviewed as time and availability permit.
If a report is confirmed, reasonable efforts may be made to investigate, mitigate, or resolve the issue.
Response times, acknowledgements, and fixes are not guaranteed.
Safe Harbor
Security researchers acting in good faith to identify and report vulnerabilities will not be considered to be engaging in unauthorized activity provided that:
- Testing does not intentionally harm the website.
- Testing does not disrupt availability.
- No data is modified or destroyed.
- No information is publicly disclosed before review.
- Findings are reported responsibly.
Disclaimer
This project is provided
"AS IS"
without warranty of any kind.
While reasonable efforts may be made to maintain security and integrity, no guarantees are provided regarding:
- Security
- Availability
- Reliability
- Fitness for a particular purpose
- Protection from all vulnerabilities
Policy Updates
This Security Policy may be modified, updated, or replaced at any time without prior notice.
Continued use of the project following publication of changes constitutes acceptance of the updated policy.