Skip to content

Security: avaluev/avaluev.github.io

Security

SECURITY.md

Security policy

Reporting a vulnerability

If you discover a security issue with this site or any of the build scripts in this repository, please report it privately rather than opening a public issue.

Please include:

  1. A clear description of the issue.
  2. Steps to reproduce.
  3. The potential impact.
  4. Any suggested mitigation, if you have one.

Response time

First acknowledgement within 48 hours on workdays. A fix or mitigation plan within 7 days for issues affecting the live site, longer for issues in the build tooling that have no public-facing impact.

Scope

In scope:

  • The deployed site at https://avaluev.github.io/ and any of its assets.
  • The build scripts under scripts/.

Out of scope:

  • Issues in third-party services that are linked from the site (LinkedIn, Telegram, YouTube, GitHub).
  • Issues that require physical access to the maintainer's devices.

Acknowledgement

Reporters who follow this process and act in good faith will be acknowledged in the changelog of the resulting fix unless they prefer to remain anonymous.

There aren't any published security advisories