Most of my public repositories are small portfolio projects, demos, prototypes, or learning projects. Unless a repository states otherwise, only the default branch of actively maintained repositories is in scope for security reports.
| Project type | Security support |
|---|---|
| Actively maintained apps, CLIs, and libraries | Best-effort review and fixes |
| Archived repositories | Not supported |
| Experimental prototypes | Best-effort review only |
| Forks or third-party deployments | Not supported |
Do not publish exploit details in a public issue or pull request.
Preferred reporting path:
- Use GitHub private vulnerability reporting when it is enabled for the affected repository.
- If private vulnerability reporting is not available, contact me through a private channel linked from my GitHub profile and include the affected repository name.
Please include:
- Affected repository and branch.
- Vulnerability type and impact.
- Reproduction steps or proof of concept.
- Whether the issue affects a live deployment.
- Any suggested mitigation.
I will review valid reports on a best-effort basis. For portfolio and prototype repositories, the likely outcome may be a fix, a dependency update, a configuration change, or clearer documentation about the project boundary.
- Automated dependency reports without an exploitable path.
- Social engineering.
- Denial-of-service testing against live services.
- Reports requiring access to private systems, private data, or third-party accounts.