Skip to content

Security: vesivanov/gsc-data-dive

Security

SECURITY.md

Security Policy

Supported Versions

This project is currently maintained on the main branch only.

Version Supported
main Yes
older snapshots No

Reporting a Vulnerability

Do not open a public GitHub issue for suspected vulnerabilities.

Report security issues privately to the maintainer before public disclosure. Include:

  • A clear description of the issue
  • Reproduction steps or a proof of concept
  • Impact assessment
  • Any suggested remediation

If the issue involves exposed credentials or third-party account access, rotate affected credentials immediately and note that in the report.

Response Process

  • I will acknowledge receipt as soon as practical.
  • I will validate the report and determine severity.
  • If the report is valid, I will prepare and ship a fix before public disclosure where possible.
  • Once a fix is available, I may publish a changelog entry or advisory describing the issue at a high level.

Scope Notes

This repository contains a browser app and Netlify serverless functions. Reports are especially helpful for:

  • Authentication and session handling flaws
  • CSRF, XSS, injection, SSRF, and data exposure issues
  • Dependency and supply-chain risks
  • Privacy or unsafe default configuration problems

There aren't any published security advisories