Skip to content

Security: sthsuyash/Nepali-news-portal

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it to us as soon as possible. Here's how to do it:

  1. Contact: Please send your findings to Suyash S., Amish B., Prashanna B.S. or use the [security contact form] if available.
  2. Response Time: We will acknowledge your report as soon as possible and aim to provide an update on the status of the issue.
  3. What Happens Next: After the vulnerability is reported:
    • If accepted, we will work on a fix and release a patch in the next available version.
    • If declined, we will explain why the issue was not considered a security threat.
  4. Disclosure Timeline: We will not disclose details of the vulnerability publicly until a fix has been applied or there is an agreed-upon disclosure timeline.

Please do not open issues directly in the repository for security vulnerabilities. Use the above contact method to ensure a secure and private communication channel.

Security Updates

We recommend regularly updating to the latest stable release to benefit from security patches and fixes. Security updates will be announced in the release notes and via GitHub.

Security Best Practices

To enhance security, please follow the best practices outlined below:

  • Always use the latest supported version of the project.
  • Regularly audit your environment for security risks.
  • Use strong access controls and avoid exposing sensitive data in code.

There aren’t any published security advisories