Skip to content

Security: chahe-dridi/dev-setup

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do NOT open a public GitHub issue for security vulnerabilities.

We take security issues seriously and appreciate your responsible disclosure.

How to Report

Email: chaher.dridi@esprit.tn

Or use GitHub's private vulnerability reporting feature:

  1. Go to the Security tab of this repository
  2. Click Report a vulnerability
  3. Provide details about the vulnerability

What to Include

When reporting a security issue, please include:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Impact assessment (what could an attacker do?)
  • Affected versions (if known)
  • Screenshots or logs (if applicable)

Response Time

  • Initial response: Within 48 hours
  • Status updates: Every 7 days
  • Resolution timeline: Depends on severity (critical issues prioritized)

Security Update Process

  1. We will acknowledge your report within 48 hours
  2. Our team will investigate and validate the issue
  3. We will develop and test a fix
  4. Once resolved, we will notify you and publish a security advisory (if appropriate)

Security Best Practices

  • Keep your dependencies up to date
  • Use strong, unique passwords
  • Enable two-factor authentication (2FA)
  • Review and audit third-party integrations

Thank you for helping keep our project secure! 🛡️

There aren’t any published security advisories