This repository is a reusable project baseline rather than a deployed application. Security fixes are applied to the current default branch.
| Target | Supported |
|---|---|
Current main branch |
Yes |
| Older commits or unmaintained tags | No |
| Projects created from this template | Maintained by their respective owners |
Derived projects must define and operate their own security policy. A fix in this boilerplate is not automatically propagated to repositories created from it.
Do not open a public issue for a suspected vulnerability.
Use GitHub's
private vulnerability reporting
as the preferred reporting channel. If that channel is unavailable, send a
private report to
s.emad.helmi@gmail.com with a subject beginning
with [SECURITY].
Include, when available:
- the affected file, component, or workflow;
- the impact and realistic attack scenario;
- steps or a minimal proof of concept;
- affected versions or commits;
- a proposed mitigation;
- whether the issue has been disclosed elsewhere.
Do not include real credentials, personal data, or third-party secrets in the report.
The maintainer aims to acknowledge a report within seven calendar days and provide an initial status within fourteen calendar days. These targets are not a guaranteed service-level agreement.
Please allow reasonable time for investigation and remediation before public disclosure. When a report is accepted, disclosure and credit will be coordinated with the reporter unless safety, privacy, or legal constraints require another approach.
Reports that concern a derived project should be sent to that project's maintainer unless the underlying issue is present in this boilerplate.