Security Policy
This repository primarily contains documentation, GitHub Pages configuration, and GitHub Actions workflows. Security reports are still relevant where project files or contribution processes could expose users or repository access.
Supported content
Security review applies to the current main branch and active GitHub Pages deployment. Historical documentation is not maintained as a separately supported release line.
Report privately
Use GitHub’s private security-advisory feature when available. Do not open a public issue containing:
- access tokens, credentials, cookies, or private keys;
- private email addresses or personal information;
- sponsorship or billing information;
- exploitable workflow details that have not been remediated;
- malicious URLs that could put readers at risk.
Relevant reports
Examples include:
- unsafe or over-privileged GitHub Actions workflows;
- dependency or action-pin risks;
- credential or private-data exposure;
- deceptive links, redirect abuse, or malicious embedded content;
- repository configuration that enables unauthorised modification;
- instructions that materially facilitate account abuse.
Out of scope
Ordinary documentation corrections, disputed achievement thresholds, formatting defects, and non-sensitive broken links should use the standard issue forms.
Response process
Maintainers will assess scope, minimise exposure, prepare a corrective change, and document the public-facing remediation once disclosure is safe. Reporter credit will be offered unless anonymity is requested.