Skip to content

Security: husnainhashmi5/sITEmED

Security

SECURITY.md

Security Policy

Supported Versions

This repository is maintained as a portfolio and application codebase. Security fixes should target the current main branch unless a release branch is explicitly created.

Reporting A Vulnerability

Do not open public issues containing secrets, customer data, database dumps, credentials, or exploit details. Report privately to the repository owner with:

  • affected area
  • impact
  • reproduction steps
  • suggested mitigation if known

Secret Handling

Never commit:

  • .env files
  • database dumps
  • client documents
  • generated reports
  • AWS keys
  • Mailgun keys
  • ActiveCampaign tokens
  • proxy credentials
  • Cochrane credentials
  • AI service keys

If a secret is exposed, rotate it immediately and remove it from active configuration. Do not rewrite history without explicit approval.

There aren't any published security advisories