Skip to content

Security: kunalkeshan/kumar-srivathsan

Security

SECURITY.md

Security Policy

Scope

This policy applies to the source code in this repository. The following are out of scope:

  • The live site's hosting infrastructure (Vercel)
  • Third-party services integrated into the site (Google Analytics, Microsoft Clarity)
  • Issues with dependencies that are already publicly disclosed upstream

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Instead, use one of these private channels:

  1. GitHub Security Advisories (preferred) — go to the Security tab of this repository and submit a private advisory.
  2. GitHub profile — reach out via https://github.com/kunalkeshan.

What to include in your report

  • A description of the vulnerability and its potential impact
  • The affected component or file(s)
  • Steps to reproduce the issue
  • Any suggested fix or mitigation (optional but appreciated)

Response Timeline

Step Target
Acknowledgement Within 7 days of receiving the report
Fix or workaround timeline communicated Within 30 days
Public disclosure After a fix is available, coordinated with the reporter

Disclosure Policy

This project follows coordinated disclosure. Please allow reasonable time for a fix before publishing details of the vulnerability. Reporters who follow this policy will be credited in the fix unless they prefer to remain anonymous.

There aren't any published security advisories