This repository contains the Coastal Peaks Air Service website and related operational documentation. This document explains how to report a vulnerability and what to expect.
Fixes are applied to the latest version on main.
| Version | Supported |
|---|---|
Latest on main |
Yes |
| Older commits | No |
| Forks | No |
Please do not open a public issue for security problems.
- GitHub Private Vulnerability Reporting (preferred). Use the Report a vulnerability button on the Security tab.
- Email. Email chalwk.dev@gmail.com with "SECURITY" in the subject line.
- A clear description of the issue
- Steps to reproduce
- The impact you believe it has
- Whether you've disclosed it anywhere else
Redact any personal data or member information from what you send.
- Vulnerabilities in the Jekyll site (dependency issues, XSS in templates, unsafe includes, broken redirects that could leak data)
- Leaked secrets, API keys, or tokens in the source or build files
- Member data exposed unintentionally
- Broken authentication or access controls on any interactive feature
- Issues that require an attacker to already have access to the repository
- Uptime or availability of GitHub Pages
- Typos or content corrections (open a regular issue)
- Findings from automated scanners with no demonstrated impact
- Acknowledgement: within 7 days
- Initial assessment: within 14 days
- Fix: usually within 30 days for confirmed issues
- Public disclosure: coordinated with you
- Dependabot alerts and security updates
- Secret scanning with push protection