Skip to content

Security: Deathcharge/samsarix-field-guide

SECURITY.md

Security Policy

Supported scope

The current main branch and the published Samsarix Field Guide are supported. Destination repositories are independent projects with their own security boundaries and reporting guidance.

Report a vulnerability privately

Email support@samsarix.com with the subject Security report: Samsarix Field Guide.

Please include:

  • the affected URL, file, or commit;
  • steps to reproduce the issue;
  • the impact you believe is possible;
  • any safe proof of concept; and
  • how Samsarix LLC may contact you about the report.

Do not include secrets that are not necessary to reproduce the issue. Do not open a public issue for an unpatched vulnerability.

Samsarix LLC does not promise a bounty or fixed response deadline. We will make a good-faith effort to acknowledge a complete report, assess it, and coordinate disclosure appropriate to the risk.

Static-site boundary

This site has no account system, server-side application, database, analytics, cookies, or visitor storage. Its primary security surface is static HTML, CSS, JavaScript, GitHub Pages configuration, and outbound links. Vulnerabilities in a linked project should be reported to that project's maintainers.

There aren't any published security advisories