Skip to content

Security: zsdotcom/dotfiles

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue for security vulnerabilities.

Use GitHub's private vulnerability reporting: go to the affected repository's Security tab → Report a vulnerability. This opens a private advisory visible only to maintainers.

If you cannot use that flow, email: platform@zarishsphere.com

Include: affected repo/version, a description of the issue, and reproduction steps if possible. You will get an acknowledgment as soon as practical — this is a solo-maintainer project, so response times may vary, but security reports are the highest priority.

Scope

This applies to all repositories under the zsdotcom GitHub organization.

Data sensitivity note

Given this platform's context (health data for displaced populations), any vulnerability touching identity resolution, data export, or the emergency key-destruction protocol should be flagged as critical in your report.

There aren't any published security advisories