Skip to content

Security: gabroberge/endless-buzzwords

Security

SECURITY.md

Security Policy

Supported versions

Endless Buzzwords is currently under active development. Only the latest version is supported.

Reporting a vulnerability

If you discover a security vulnerability, please report it privately using GitHub's security advisory feature rather than opening a public issue.

Please include enough information to reproduce and understand the issue.

Scope

Endless Buzzwords is a static client-side application. It has no backend, authentication system, or database. Application data is currently stored locally in the browser.

Security issues affecting visitors, such as cross-site scripting, injection vulnerabilities, exposed secrets, or vulnerable dependencies, are in scope.

Expected application behavior, local browser persistence, missing features, and general UX issues are not security vulnerabilities.

Response

Valid reports will be reviewed as time permits. There is currently no bug bounty program.

Safe harbor

Good-faith security research is welcome. Please avoid disruptive testing against the production deployment.

There aren't any published security advisories