Skip to content

Security: sdcastillo/sdcastillo.github.io

SECURITY.md

Security Policy

πŸ›‘οΈ Welcome, Security Researchers!

Thank you for taking the time to responsibly disclose security vulnerabilities in my projects. I deeply appreciate the work of security researchers and the open-source community who help make software safer for everyone. Pleaes report security issues to "ArtificialActuary@gmail.com"

This security policy outlines how to report vulnerabilities and what to expect from me throughout the process.


🎯 Reporting a Vulnerability

If you discover a security vulnerability in any of my GitHub projects, I want to hear about itβ€”but please do so responsibly.

How to Report

Do NOT:

  • ❌ Create a public GitHub issue for the vulnerability
  • ❌ Post details on social media or public forums
  • ❌ Publicly shame or pressure for a fix

Do:

  • βœ… Report privately through GitHub's Security Advisory feature
  • βœ… Email me directly at: [Your Email] (if you prefer)
  • βœ… Include as much detail as possible
  • βœ… Give me reasonable time to respond and patch

Private Reporting via GitHub

For GitHub repositories, use GitHub's Private Vulnerability Disclosure:

  1. Go to the repository's Security tab
  2. Click "Report a vulnerability"
  3. Fill out the form with:
    • A clear description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any proof-of-concept code (if applicable)
    • Your contact information

This creates a private security advisory that only you and I can see until we're ready to publish.

Direct Email

If you prefer email or GitHub's system isn't working:

  • Email: [Your Email Address]
  • Subject Line: [SECURITY] Vulnerability in [Project Name]
  • Include:
    • Detailed vulnerability description
    • Steps to reproduce
    • Potential impact
    • Your name (optional, but appreciated)
    • How you'd like to be credited (optional)

⏱️ What to Expect

Response Timeline

  • Initial Response: Within 48 hours

    • I will acknowledge receipt of your report
    • Provide an estimated timeline for investigation
  • Investigation: 1-2 weeks (depending on complexity)

    • I will investigate the vulnerability
    • Verify the issue
    • Develop a fix
    • Test the fix thoroughly
  • Patch Release: After investigation

    • I will release a patched version
    • Create a security advisory
    • Credit the reporter (unless you prefer anonymity)
    • Publicly disclose the vulnerability details

Communication

  • I will keep you informed throughout the process
  • If I need clarification, I will reach out
  • I will notify you before making any information public
  • I welcome your input on the fix before release

πŸ“‹ Vulnerability Report Template

To help me understand and fix issues quickly, please include:

**Vulnerability Type:** (e.g., SQL Injection, XSS, Authentication Bypass, etc.)

**Project/Component:** [Project name and specific component]

**Severity:** (Critical / High / Medium / Low)

**Description:** 
[Clear description of the vulnerability]

**Steps to Reproduce:**
1. [Step 1]
2. [Step 2]
3. [etc.]

**Expected Behavior:**
[What should happen]

**Actual Behavior:**
[What actually happens]

**Proof of Concept:**
[Code, screenshots, or video demonstrating the issue]

**Potential Impact:**
[What could an attacker do with this vulnerability?]

**Affected Versions:**
[Which versions are vulnerable?]

**Your Contact Information:**
[How can I reach you? Name is optional]

βœ… Supported Versions

Security updates are provided for:

Project Latest Version Status
sdcastillo.github.io Current βœ… Active
SamSoundsVibes Current βœ… Active
SamSoundsVibes (PassMyExam Legacy) Varies ⚠️ Limited Support

For details on support status for specific projects, please check each repository's README.


πŸ™ Responsible Disclosure Guidelines

I follow responsible disclosure best practices and expect the same from reporters:

  1. Confidentiality - Keep vulnerability details confidential until patched and disclosed
  2. Good Faith - Only test the vulnerability on systems you own or have permission to test
  3. No Exploitation - Do not access, modify, or delete data beyond what's needed to prove the vulnerability
  4. No Disruption - Do not disrupt service availability or performance
  5. Patience - Give me reasonable time to investigate and patch

πŸ† Recognition & Credit

I will gladly credit you for responsibly disclosing vulnerabilities, including:

  • Your name (if you want it public)
  • Your website or social media
  • A link to your GitHub profile
  • In the security advisory
  • In the release notes

If you prefer anonymity, that's completely fineβ€”just let me know.


πŸ“œ Legal

Safe Harbor: If you follow this security policy in good faith, I will not pursue legal action against you, including under the Computer Fraud and Abuse Act (CFAA) or similar laws.

You will not be held liable for:

  • Testing vulnerabilities on systems you own or have permission to test
  • Accessing or modifying data only to the extent necessary to demonstrate the vulnerability
  • Temporarily affecting system availability during testing (if done responsibly)

Limitations:

  • Testing must be limited to the project(s) in scope
  • Do not access or modify data belonging to other users or projects
  • Do not test on production systems without explicit permission

🀝 Let's Work Together

Security research is a partnership. I'm committed to:

βœ… Responding promptly to reports βœ… Treating researchers with respect βœ… Crediting contributors appropriately βœ… Fixing vulnerabilities quickly βœ… Being transparent about the process

Thank you for helping keep my projects secure! πŸ™Œ


πŸ“ž Questions?

If you have questions about this policy or the vulnerability disclosure process:

  • Email: [Your Email]
  • GitHub Issues: [Non-sensitive questions only]
  • Twitter/X: @SamSoundsVibes

Last Updated: November 25, 2025 Version: 1.0

There aren't any published security advisories