Skip to content

Security: AnimeshShaw/AppSec-Atlas

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in AppSec Atlas (including the website infrastructure, any lab components, or tooling), please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

How to Report

Email: security@appsecatlas.com

Include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your recommended fix (optional but appreciated)

Response Timeline

Phase Timeline
Acknowledgement Within 48 hours
Initial assessment Within 5 business days
Fix or mitigation Within 30 days (critical: 7 days)
Public disclosure After fix is deployed

Scope

In scope:

  • The AppSec Atlas website (appsecatlas.com)
  • CI/CD pipeline misconfigurations
  • Lab Docker images with unintended real vulnerabilities

Out of scope:

  • Intentional vulnerabilities in lab exercises (they are designed to be vulnerable for educational purposes)
  • Third-party services we use (report directly to them)

Hall of Fame

Security researchers who responsibly disclose valid vulnerabilities will be credited in our Security Hall of Fame (with their permission).

Thank you for helping keep AppSec Atlas safe! 🔐

There aren't any published security advisories