Thank you for taking the time to responsibly disclose security vulnerabilities in my projects. I deeply appreciate the work of security researchers and the open-source community who help make software safer for everyone. Pleaes report security issues to "ArtificialActuary@gmail.com"
This security policy outlines how to report vulnerabilities and what to expect from me throughout the process.
If you discover a security vulnerability in any of my GitHub projects, I want to hear about itβbut please do so responsibly.
Do NOT:
- β Create a public GitHub issue for the vulnerability
- β Post details on social media or public forums
- β Publicly shame or pressure for a fix
Do:
- β Report privately through GitHub's Security Advisory feature
- β Email me directly at: [Your Email] (if you prefer)
- β Include as much detail as possible
- β Give me reasonable time to respond and patch
For GitHub repositories, use GitHub's Private Vulnerability Disclosure:
- Go to the repository's Security tab
- Click "Report a vulnerability"
- Fill out the form with:
- A clear description of the vulnerability
- Steps to reproduce
- Potential impact
- Any proof-of-concept code (if applicable)
- Your contact information
This creates a private security advisory that only you and I can see until we're ready to publish.
If you prefer email or GitHub's system isn't working:
- Email: [Your Email Address]
- Subject Line:
[SECURITY] Vulnerability in [Project Name] - Include:
- Detailed vulnerability description
- Steps to reproduce
- Potential impact
- Your name (optional, but appreciated)
- How you'd like to be credited (optional)
-
Initial Response: Within 48 hours
- I will acknowledge receipt of your report
- Provide an estimated timeline for investigation
-
Investigation: 1-2 weeks (depending on complexity)
- I will investigate the vulnerability
- Verify the issue
- Develop a fix
- Test the fix thoroughly
-
Patch Release: After investigation
- I will release a patched version
- Create a security advisory
- Credit the reporter (unless you prefer anonymity)
- Publicly disclose the vulnerability details
- I will keep you informed throughout the process
- If I need clarification, I will reach out
- I will notify you before making any information public
- I welcome your input on the fix before release
To help me understand and fix issues quickly, please include:
**Vulnerability Type:** (e.g., SQL Injection, XSS, Authentication Bypass, etc.)
**Project/Component:** [Project name and specific component]
**Severity:** (Critical / High / Medium / Low)
**Description:**
[Clear description of the vulnerability]
**Steps to Reproduce:**
1. [Step 1]
2. [Step 2]
3. [etc.]
**Expected Behavior:**
[What should happen]
**Actual Behavior:**
[What actually happens]
**Proof of Concept:**
[Code, screenshots, or video demonstrating the issue]
**Potential Impact:**
[What could an attacker do with this vulnerability?]
**Affected Versions:**
[Which versions are vulnerable?]
**Your Contact Information:**
[How can I reach you? Name is optional]
Security updates are provided for:
| Project | Latest Version | Status |
|---|---|---|
| sdcastillo.github.io | Current | β Active |
| SamSoundsVibes | Current | β Active |
| SamSoundsVibes (PassMyExam Legacy) | Varies |
For details on support status for specific projects, please check each repository's README.
I follow responsible disclosure best practices and expect the same from reporters:
- Confidentiality - Keep vulnerability details confidential until patched and disclosed
- Good Faith - Only test the vulnerability on systems you own or have permission to test
- No Exploitation - Do not access, modify, or delete data beyond what's needed to prove the vulnerability
- No Disruption - Do not disrupt service availability or performance
- Patience - Give me reasonable time to investigate and patch
I will gladly credit you for responsibly disclosing vulnerabilities, including:
- Your name (if you want it public)
- Your website or social media
- A link to your GitHub profile
- In the security advisory
- In the release notes
If you prefer anonymity, that's completely fineβjust let me know.
Safe Harbor: If you follow this security policy in good faith, I will not pursue legal action against you, including under the Computer Fraud and Abuse Act (CFAA) or similar laws.
You will not be held liable for:
- Testing vulnerabilities on systems you own or have permission to test
- Accessing or modifying data only to the extent necessary to demonstrate the vulnerability
- Temporarily affecting system availability during testing (if done responsibly)
Limitations:
- Testing must be limited to the project(s) in scope
- Do not access or modify data belonging to other users or projects
- Do not test on production systems without explicit permission
Security research is a partnership. I'm committed to:
β Responding promptly to reports β Treating researchers with respect β Crediting contributors appropriately β Fixing vulnerabilities quickly β Being transparent about the process
Thank you for helping keep my projects secure! π
If you have questions about this policy or the vulnerability disclosure process:
- Email: [Your Email]
- GitHub Issues: [Non-sensitive questions only]
- Twitter/X: @SamSoundsVibes
Last Updated: November 25, 2025 Version: 1.0