Skip to content

Security: cyberskill-official/.github

Security

docs/SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please follow these steps:

Preferred Method: GitHub Private Advisories

  1. Go to the Security tab of the affected repository
  2. Click "Report a vulnerability"
  3. Fill in the details and submit

This keeps the report private and allows us to collaborate on a fix before public disclosure.

Alternative: Email

If you cannot use GitHub Advisories, email us at security@cyberskill.world with:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fix (optional)

Response Timeline

Stage Timeline
Acknowledgment Within 48 hours
Initial Assessment Within 5 days
Fix & Release Within 30 days

Responsible Disclosure

  • Please do not open a public issue for security vulnerabilities
  • We will credit reporters in the release notes (unless anonymity is requested)
  • We follow coordinated vulnerability disclosure

Encrypted Communication

If you need to share sensitive details (exploit code, credentials, server info), you can encrypt your report:

  • PGP: Request our public key by emailing security@cyberskill.world with subject "PGP Key Request"
  • GitHub Security Advisories: The preferred method — GitHub handles encryption automatically

There aren’t any published security advisories