Skip to content

Security: orcfax/static-archive-viewer

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a vulnerability, please do not open a public issue. Instead, follow these steps:

  1. Confidential Reporting: Send an email to [email protected] with the subject line: "Security Vulnerability Report."
  2. Provide Details: Include detailed information about the vulnerability:
    • Description of the issue
    • Steps to reproduce
    • Potential impact
    • Any relevant logs or screenshots

Response Time

We are committed to responding to vulnerability reports promptly:

  • Acknowledgment: Within 48 hours of receipt.
  • Investigation: We will investigate the issue and provide feedback or ask for additional information.
  • Resolution: Aim to release a fix within 7 days, depending on the complexity.

Disclosure Policy

To protect our users, we request that you:

  • Do Not Publicly Disclose: Refrain from sharing the vulnerability details publicly until we have released a fix.
  • Coordinate Release: We may coordinate with you to release a joint statement or credit you in our release notes, if you wish.

Scope

The following components are within the scope of our security policy:

  • Frontend Application: All Svelte code in this repository.

Out-of-scope items include:

  • Third-Party Dependencies: Vulnerabilities in external libraries should be reported to their respective maintainers.
  • User Environment Issues: Problems caused by user-specific configurations or environments.

Acknowledgments

We appreciate the efforts of security researchers and users who help us maintain the security of our project. Thank you for contributing to the safety and integrity of our application.

Contact

For any questions regarding this security policy, please contact us at [email protected].

There aren’t any published security advisories