This policy applies to the source code in this repository. The following are out of scope:
- The live site's hosting infrastructure (Vercel)
- Third-party services integrated into the site (Google Analytics, Microsoft Clarity)
- Issues with dependencies that are already publicly disclosed upstream
Do not open a public GitHub issue for security vulnerabilities.
Instead, use one of these private channels:
- GitHub Security Advisories (preferred) — go to the Security tab of this repository and submit a private advisory.
- GitHub profile — reach out via https://github.com/kunalkeshan.
- A description of the vulnerability and its potential impact
- The affected component or file(s)
- Steps to reproduce the issue
- Any suggested fix or mitigation (optional but appreciated)
| Step | Target |
|---|---|
| Acknowledgement | Within 7 days of receiving the report |
| Fix or workaround timeline communicated | Within 30 days |
| Public disclosure | After a fix is available, coordinated with the reporter |
This project follows coordinated disclosure. Please allow reasonable time for a fix before publishing details of the vulnerability. Reporters who follow this policy will be credited in the fix unless they prefer to remain anonymous.