Skip to content

Conversation

@SameerSenapati17
Copy link

@SameerSenapati17 SameerSenapati17 commented Aug 10, 2025

What type of PR is this? (check all applicable)

  • Refactor
  • Feature
  • Bug Fix
  • Enhancement
  • Documentation Update

What I did

@vercel
Copy link

vercel bot commented Aug 10, 2025

@SameerSenapati17 is attempting to deploy a commit to the Mauro de Souza's projects Team on Vercel.

A member of the Team first needs to authorize it.

Copy link
Author

@SameerSenapati17 SameerSenapati17 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Policy

@alettsy
Copy link
Contributor

alettsy commented Oct 25, 2025

I can't contribute changes to your PR, but what about something like this for the SECURITY.md file?

# Security Policy

## Supported versions

All code in this repository is in active development and is deployed continuously to Vercel. There are no formal releases or tagged versions. When reporting a vulnerability, please indicate the commit SHA or branch (e.g., main) and the date/time you observed the issue.

## Reporting a vulnerability

We do not currently provide a confidential reporting email or private disclosure channel. To report a security issue, please open a **public GitHub issue** in this repository with the label "security". If you cannot add that label yourself, include the word "security" in the issue title.

When opening an issue, include:

- Short summary of the issue
- Affected component(s) (frontend, API, dependencies, deployment)
- Steps to reproduce (minimum reproducible example)
- Expected vs actual behavior
- Request/response samples or logs (redact any sensitive data)
- Commit SHA, branch, or timestamp where applicable
- Suggested severity (Low / Medium / High / Critical) and reason

If you prefer not to disclose exploit details publicly, state that in the issue and we will respond with guidance on how to proceed; note that we cannot guarantee a fully private channel at this time.

## Response process

We will try to assess any reported vulnerabilities as soon as possible and prioritize fixing them.

## Severity classification (guidance only)

- **Critical**: Remote code execution, or compromise of infrastructure
- **High**: Privilege escalation, or data leaks
- **Medium**: Information disclosure with limited impact, CSRF on non-sensitive actions
- **Low**: Minor issues, best-practice recommendations, or UI inconsistencies

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants