Skip to content

Security: supunlakmal/hash-calendar

SECURITY.md

Security Policy

Supported versions

Security updates are applied to the main branch.

Version Supported
main Yes
Older snapshots/forks No

Reporting a vulnerability

Please report security vulnerabilities privately.

Please do not post exploit details in public issues.

What to include in a report

  • Affected component(s)
  • Reproduction steps or proof of concept
  • Impact assessment (confidentiality/integrity/availability)
  • Suggested mitigation (if known)

Response process

  • Initial triage target: within 7 days
  • If confirmed, a fix will be prepared and coordinated for disclosure
  • Credit will be given unless you request anonymity

Scope notes for this project

hash-calendar is a client-only app with URL-hash state. Security-relevant areas include:

  • Encryption/decryption behavior
  • URL hash parsing/handling
  • Data import parsing (.ics, JSON bridge)
  • Third-party script loading and integration

There aren't any published security advisories