What's Missing
DevCard handles user contact data and profile information but has no SECURITY.md or responsible disclosure policy. This is a GitHub best practice for any public repo handling personal data.
Proposed Content for SECURITY.md
- Supported versions table
- How to report a security vulnerability (email or GitHub private security advisory)
- Expected response timeline
- What qualifies as in-scope (data leakage, auth bypass, XSS)
- Out-of-scope items (rate limiting, spam)
- Acknowledgement policy for responsible reporters
Why This Matters
DevCard stores contact info, social links, and potentially business data. A clear disclosure path builds user trust and helps maintainers handle reports efficiently.
What's Missing
DevCard handles user contact data and profile information but has no
SECURITY.mdor responsible disclosure policy. This is a GitHub best practice for any public repo handling personal data.Proposed Content for SECURITY.md
Why This Matters
DevCard stores contact info, social links, and potentially business data. A clear disclosure path builds user trust and helps maintainers handle reports efficiently.