Skip to content

Security: Khashana22/pentest

Security

SECURITY.md

Security Policy

Overview

This repository contains the source code for a professional cybersecurity portfolio. It is a Next.js SSR web application and does not handle sensitive user data.

Supported Versions

Version Supported
main branch Active

Reporting a Vulnerability

Do NOT open a public GitHub Issue for security vulnerabilities.

Contact directly via email: syedkhashana22@gmail.com Subject: [SECURITY] Portfolio Vulnerability Report

Include: description, steps to reproduce, potential impact, and suggested fix.

Scope

  • XSS or injection in the deployed portfolio site
  • Exposed secrets or credentials in the repository
  • Security misconfigurations in deployment

Not in Scope

  • Self-XSS
  • Theoretical vulnerabilities without demonstrated impact
  • Issues in third-party platforms (Netlify, GitHub, Upwork, LinkedIn)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 5 business days

Responsible disclosure is respected. Credit will be given upon request.

There aren't any published security advisories