Skip to content

Security: HorebZ/CDM-2026

Security

SECURITY.md

Security Policy

Supported versions

This is a single-maintainer fan project. Only the latest main branch is actively maintained.

Reporting a vulnerability

If you think you have found a security issue (for example an XSS, a dependency with a known CVE that clearly affects this site, or anything that could harm users):

  1. Please do not open a public issue.
  2. Contact the maintainer privately via GitHub (@HorebZ), for instance through a private message or by opening a GitHub security advisory on this repository.
  3. Include enough detail to reproduce the issue (URL, steps, expected vs actual behaviour).

You can expect a best-effort response within a reasonable delay. As this is a hobby project, there is no formal SLA, but security-related reports are taken seriously and prioritised over regular issues.

Scope

This project is a static fan site; it does not process personal data, does not expose a backend API, and does not store user credentials. Reports focused on user-impacting vulnerabilities in the deployed site or in the repository tooling are the most relevant.

There aren’t any published security advisories