Skip to content

Security: Sunhaiy/reflexweb

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open public issues for security-sensitive problems.

Instead, report them privately to the maintainer with:

  • a short summary of the issue
  • affected file or page
  • impact description
  • reproduction steps
  • screenshots or proof of concept when helpful

Response Goals

The project aims to:

  • acknowledge the report promptly
  • reproduce and assess the issue
  • decide whether the fix should be silent or public
  • ship a correction in a reasonable timeframe

Good Examples of Security Reports

  • exposed secrets or tokens
  • unsafe external script usage
  • download-link tampering
  • XSS or injection risks
  • privacy issues in tracking, metadata, or third-party embeds

Please Avoid

  • publishing exploit details before a fix is ready
  • opening duplicate public issues for sensitive topics
  • sharing private credentials in screenshots

There aren't any published security advisories