Skip to content

Security: wasifmostofa/ICT_Practical_SJC

SECURITY.md

πŸ” Security Policy

Thanks for your interest in the security of this project. I take all reports of potential vulnerabilities seriously and appreciate your help in keeping things safe.

πŸ“¦ Supported Versions

I currently maintain only the latest version of this project.

Version Supported
latest βœ…
older ❌

πŸ“£ Reporting a Vulnerability

Important

If you find a security issue, please open a issue.
Or, you can report it privately to me through one of the following:

Please include:

  • A clear description of the issue
  • Steps to reproduce, if possible
  • Any logs, screenshots, or other helpful context

I’ll do my best to respond within 3–5 business days.

❌ What Will Get a Report Declined

To keep things focused and productive, I will not accept reports that fall into the following categories:

  • Reports about outdated dependencies without a clear, exploitable vulnerability
  • Theoretical issues with no real-world impact or proof-of-concept
  • Automated scanner output without actionable context or explanation
  • Denial of Service (DoS) attacks that require unrealistic conditions (e.g., unlimited input or traffic)
  • Issues that are already publicly known and documented
  • Social engineering, phishing, or physical security vulnerabilities
  • Reports targeting third-party services, infrastructure, or tools not maintained in this repository

If you're unsure whether something qualifies, feel free to ask β€” better safe than sorry.

🀝 Responsible Disclosure

I kindly ask that you:

  • Give me time to investigate and patch the issue before disclosing it publicly
  • Avoid testing in ways that could negatively affect users or services
  • Keep the information confidential until it has been addressed

Thank you for helping make this project safer for everyone πŸ™

There aren’t any published security advisories