Skip to content

docs: add SECURITY.md with vulnerability disclosure policy #620

Description

@Nareshkumawat-star

What's Missing

DevCard handles user contact data and profile information but has no SECURITY.md or responsible disclosure policy. This is a GitHub best practice for any public repo handling personal data.

Proposed Content for SECURITY.md

  1. Supported versions table
  2. How to report a security vulnerability (email or GitHub private security advisory)
  3. Expected response timeline
  4. What qualifies as in-scope (data leakage, auth bypass, XSS)
  5. Out-of-scope items (rate limiting, spam)
  6. Acknowledgement policy for responsible reporters

Why This Matters

DevCard stores contact info, social links, and potentially business data. A clear disclosure path builds user trust and helps maintainers handle reports efficiently.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions