Skip to content

Security: arnayshukla/resumeit

Security

SECURITY.md

Security Policy

Supported versions

  • This is a hobby project. Security fixes are best-effort and will generally land on main.

Reporting a vulnerability

  • Do not open a public issue for security-sensitive reports.
  • Email: security@arnayshukla.com (or DM me on LinkedIn if email bounces).

Include:

  • What you found and impact (what an attacker can do)
  • Repro steps (requests, payloads, screenshots)
  • Any logs/stack traces (redact tokens/PII)

Threat model (what we defend against)

  • Leaked API keys / credentials
  • Abuse of OpenAI-backed endpoints (cost spikes / DoS)
  • Unauthorized access to user resumes (PII)

Non-goals

  • This is not intended to meet enterprise compliance requirements.

There aren't any published security advisories