Skip to content

Security: Code-the-Dream-School/summer-26-js-practicum-team2

.github/SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to active development branches only:

  • main
  • development

Older branches or tags may not receive security updates.

Reporting a Vulnerability

Please do not open a public GitHub issue for suspected security vulnerabilities.

Use one of the private channels below:

  1. Create a private security advisory in this repository (preferred).
  2. Contact a maintainer directly and include "Security" in the subject.

Private advisory link: https://github.com/code-the-dream-school/summer-26-js-practicum-team2/security/advisories/new

If a public issue is created accidentally, keep details minimal and move to a private advisory as soon as possible.

If you are unsure whether something is a vulnerability, report it anyway.

What to Include

Please include as much of the following as possible:

  • A clear description of the issue
  • Steps to reproduce
  • Affected area (frontend, backend, or both)
  • Potential impact
  • Any proof-of-concept details (screenshots, logs, payloads)
  • Suggested fix, if you have one

Response Timeline

  • Initial acknowledgment: within 3 business days
  • Triage decision: within 7 business days
  • Fix timeline: depends on severity and complexity

We will keep reporters informed during triage and remediation.

Disclosure

Please wait for confirmation that a fix is available before public disclosure.

After remediation, we may publish a summary of the issue and resolution.

There aren't any published security advisories