Skip to content

Security: ntious/Information-Security-Assurance-Labs

SECURITY.md

Security Policy

Thank you for taking the time to help keep this repository and its users safe.

This repository is used for teaching Information Security & Assurance and does not contain production systems, private student data, or real infrastructure. However, we still care about good security practices.


🚨 Reporting a Vulnerability

If you believe you have found a security issue (for example: a leaked secret, an unsafe script, or a vulnerable dependency):

  1. Do NOT open a public issue or pull request describing the vulnerability.

  2. Instead, please contact the maintainer privately at:

    Email: ntious1+git@gmail.com
    GitHub: @ntious

Include:

  • A description of the issue
  • Steps to reproduce (if applicable)
  • Any relevant screenshots or logs

We will review your report, investigate, and respond as soon as possible.


🔐 Scope

Examples of issues that are in scope:

  • Exposed API keys, passwords, or access tokens
  • Hard-coded credentials in scripts or configuration files
  • Insecure default configurations in lab materials that could leak data if reused in the real world
  • Vulnerable dependencies used in the examples (especially if they’re exploitable by students)

Out of scope for this educational repo:

  • Intentional vulnerabilities included for lab exercises
  • Issues that only affect a student’s local environment (e.g., weak passwords they choose for themselves)
  • Theoretical vulnerabilities that cannot be reasonably exploited in this context

🧑‍🏫 Student Guidance

  • Do not commit any personal, institutional, or production secrets to this repository or to your forks.
  • Treat all example keys and passwords in the labs as fake and for educational use only.
  • If you accidentally commit a real secret, contact the maintainer immediately so it can be revoked and rotated.

Thank you for helping us maintain a safe and responsible learning environment. Please email: ntious1+git@gmail.com We will review and patch any findings.

There aren't any published security advisories