Skip to content

Security: ggauravky/Dev-Portfolio

Security

SECURITY.md

Security Policy

Supported Versions

We actively maintain and provide security updates for the following versions of Dev-Portfolio:

Version Supported
6.x ✅ Currently Active
5.x ❌ End of Support
< 5.0 ❌ End of Support

Reporting a Vulnerability

We take the security of our application, API backend, user authentication flows, and payment integrations seriously.

If you discover a security vulnerability, please follow responsible disclosure guidelines:

  1. Do NOT open a public GitHub issue for security vulnerabilities.
  2. Email your findings directly to the lead maintainer:
    • Email: kumar.gaurav.yadav2007@gmail.com
    • Subject: [SECURITY VULNERABILITY] Dev-Portfolio
  3. Provide detailed steps to reproduce the issue, proof of concept (PoC), and potential impact.

Response & Disclosure Timeline

  • Initial Acknowledgment: Within 24 hours.
  • Triage & Risk Assessment: Within 48 hours.
  • Fix & Patch Release: Within 7 business days for high/critical vulnerabilities.
  • Public Disclosure: After the patch has been deployed to production.

Thank you for helping keep our open-source software secure!

There aren't any published security advisories