Skip to content

docs: add SECURITY.md with vulnerability disclosure policy #620

@Nareshkumawat-star

Description

@Nareshkumawat-star

What's Missing

DevCard handles user contact data and profile information but has no SECURITY.md or responsible disclosure policy. This is a GitHub best practice for any public repo handling personal data.

Proposed Content for SECURITY.md

  1. Supported versions table
  2. How to report a security vulnerability (email or GitHub private security advisory)
  3. Expected response timeline
  4. What qualifies as in-scope (data leakage, auth bypass, XSS)
  5. Out-of-scope items (rate limiting, spam)
  6. Acknowledgement policy for responsible reporters

Why This Matters

DevCard stores contact info, social links, and potentially business data. A clear disclosure path builds user trust and helps maintainers handle reports efficiently.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions