Security Protocol
Responsible disclosure guidelines for reporting security vulnerabilities.
01. Scope
This security policy applies to the following assets:
raoufabedini.dev— This portfolio website- Any open-source repositories under
github.com/Raoof128
02. What to Report
In Scope
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Security misconfigurations
- Information disclosure
- Authentication/authorization flaws
- Injection vulnerabilities
Out of Scope
- Social engineering attacks
- Physical security issues
- Denial of Service (DoS/DDoS)
- Spam or phishing attempts
- Issues in third-party services
- Rate limiting issues
03. Response Timeline
Initial Response: 48-72 hours
I will acknowledge receipt of your report and provide an initial assessment.
Resolution: 7-30 days
Depending on severity, I will work to resolve the issue within this timeframe.
Disclosure: Coordinated
We will coordinate public disclosure after the fix is deployed.
04. Responsible Disclosure Guidelines
- 1.Do not access, modify, or delete data that does not belong to you.
- 2.Do not perform attacks that could harm the availability of services.
- 3.Provide sufficient information to reproduce the vulnerability.
- 4.Give reasonable time to address the issue before public disclosure.
- 5.Act in good faith and avoid privacy violations.
05. Acknowledgments
I appreciate responsible security researchers who help improve the security of my projects. Valid reports may be acknowledged in the Security Hall of Fame.
Note: This is a personal portfolio project. No monetary bounties are offered, but your contribution will be recognized.