This repository is a security research / portfolio project. It demonstrates security engineering concepts and is not production-hardened. Do not deploy it as-is to handle real production data, secrets, or traffic without an independent security review.
Only the latest commit on the default branch is maintained.
| Version | Supported |
|---|---|
main (latest) |
✅ |
| older commits | ❌ |
If you discover a security issue in this project, please report it privately.
- Preferred: Open a GitHub Security Advisory (Security tab → "Report a vulnerability"). This keeps the report private until a fix is ready.
- Email: asaunders@dmcslabs.com
Please include:
- A description of the issue and its impact.
- Steps to reproduce (proof-of-concept where possible).
- Affected files, endpoints, or components.
- Any suggested remediation.
Please do not open a public issue for security-sensitive reports.
| Stage | Target |
|---|---|
| Acknowledge report | 3 business days |
| Triage & severity | 7 business days |
| Fix or mitigation plan | 30 days (severity-dependent) |
Severity is assessed using CVSS v3.1. Critical/High issues are prioritized.
In scope: source code in this repository. Out of scope: third-party dependencies (report upstream), social engineering, and any deployment a user stands up themselves.
Good-faith security research conducted in accordance with this policy is welcome. Do not access data that is not yours, degrade service for others, or violate any law. Acting in good faith under this policy, you will not be pursued for the research.