Security Policy

Supported Versions

This repository is a static Jekyll site, and the current branch is expected to be the supported version for production content.

Version/Branch Supported Notes
main :white_check_mark: Active site source
other feature branches :x: Security fixes should be merged back to main

Reporting a Vulnerability

Please report security issues privately and responsibly.

  • Preferred contact: open a private security advisory through GitHub, or contact the repository maintainer through the public project contact channel listed in the site metadata.
  • Please do not open a public GitHub issue for a vulnerability before a fix is ready to be discussed.
  • Include a clear description, reproduction steps, affected files or pages, and any potential impact.
  • We will acknowledge receipt within 5 business days when possible and provide a remediation timeline once the issue is triaged.

Security Expectations

  • Do not commit secrets, credentials, private keys, or tokens to the repository.
  • Prefer HTTPS for all externally loaded content and resources.
  • Keep GitHub Actions and dependency versions current.
  • Review any embedded scripts, analytics, or third-party widgets before publishing.

Disclosure Policy

We appreciate responsible disclosure. Security fixes will be prioritized based on severity and risk, and we will coordinate a public disclosure once a fix is available and validated.