Skip to content

Security: nyuchitech/zti-docs

SECURITY.md

Security Policy

About This Repository

This is a documentation repository for Zimbabwe Travel Information (travel-info.co.zw). It contains travel guides, destination information, and resources for visitors to Zimbabwe.

Reporting Security Issues

Website Security Issues

If you discover a security vulnerability affecting the Zimbabwe Travel Information website, please report it responsibly:

  1. Email: Report security issues privately to the repository maintainers via GitHub's private vulnerability reporting feature or by opening a confidential issue
  2. Do not publicly disclose the vulnerability until it has been addressed

Content Security Issues

If you find content that poses a security risk, such as:

  • Malicious or phishing links embedded in documentation
  • Outdated external links redirecting to harmful sites
  • Exposed sensitive information (API keys, credentials, personal data)
  • Cross-site scripting (XSS) vulnerabilities in embedded content

Please report these immediately by opening an issue with the label "security".

What We Consider Security Issues

  • Malicious code or links in documentation
  • Privacy concerns with contributed content
  • Vulnerabilities in the documentation build process
  • Exposed credentials or sensitive data

What Is NOT a Security Issue

  • Outdated travel information (use the bug report template instead)
  • Typos or grammatical errors
  • Feature requests for new content
  • General questions about Zimbabwe travel

Response Timeline

  • Acknowledgment: Within 48 hours of report
  • Initial Assessment: Within 1 week
  • Resolution: Dependent on severity and complexity

Security Best Practices for Contributors

When contributing to this documentation:

  1. Do not include sensitive personal information
  2. Verify external links before adding them
  3. Do not embed untrusted scripts or iframes
  4. Use HTTPS links whenever possible
  5. Report any suspicious content you encounter

Thank you for helping keep Zimbabwe Travel Information safe for all users.

There aren’t any published security advisories