Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Security: DhrRob/specification.website

Security

SECURITY.md

Security policy

Reporting a vulnerability

If you find a security issue in this site or the build pipeline:

Please do not open a public issue for security bugs.

What is in scope

  • The hosted site at https://specification.website and its subdomains.
  • The code in this repository (Astro source, GitHub Actions workflows, deployment configuration).

What is out of scope

  • Reports about missing security headers without a demonstrable impact — the site's headers are documented in public/_headers and the relevant spec pages.
  • Reports generated solely by automated scanners with no proof of exploit.
  • Social engineering attempts against maintainers.

Response

  • We will acknowledge a valid report within 3 business days.
  • We will work with you on a fix and disclosure timeline.
  • The disclosure window is typically 90 days from the acknowledgement, or sooner if a fix ships earlier.

Acknowledgements

Contributors who responsibly report security issues are credited in the project unless they prefer otherwise.

See also /.well-known/security.txt — the machine-readable version, per RFC 9116.

There aren't any published security advisories

AltStyle によって変換されたページ (->オリジナル) /