Security Policy
Supported Versions
This repository is a static Jekyll site, and the current branch is expected to be the supported version for production content.
| Version/Branch | Supported | Notes |
|---|---|---|
| main | :white_check_mark: | Active site source |
| other feature branches | :x: | Security fixes should be merged back to main |
Reporting a Vulnerability
Please report security issues privately and responsibly.
- Preferred contact: open a private security advisory through GitHub, or contact the repository maintainer through the public project contact channel listed in the site metadata.
- Please do not open a public GitHub issue for a vulnerability before a fix is ready to be discussed.
- Include a clear description, reproduction steps, affected files or pages, and any potential impact.
- We will acknowledge receipt within 5 business days when possible and provide a remediation timeline once the issue is triaged.
Security Expectations
- Do not commit secrets, credentials, private keys, or tokens to the repository.
- Prefer HTTPS for all externally loaded content and resources.
- Keep GitHub Actions and dependency versions current.
- Review any embedded scripts, analytics, or third-party widgets before publishing.
Disclosure Policy
We appreciate responsible disclosure. Security fixes will be prioritized based on severity and risk, and we will coordinate a public disclosure once a fix is available and validated.