We take the security of this personal portfolio website and headless blogging engine seriously. If you believe you have found a security vulnerability, please review this policy to report it responsibly.
Only the latest release version receives active security updates and patches.
| Version | Supported |
|---|---|
| >= 1.0.4 | ✅ |
| < 1.0.4 | ❌ |
Please do not report security vulnerabilities through public GitHub issues. Instead, report them privately using the process below:
- Send an email to hemlexofficial@gmail.com with the subject line
SECURITY VULNERABILITY - [Short Description]. - Include a detailed description of the vulnerability, including:
- Affected files and components.
- Step-by-step instructions to reproduce the issue (PoC code or request payloads if applicable).
- The potential impact of the vulnerability.
We will acknowledge receipt of your report within 48 hours and provide a tracking status.
Upon receiving a valid report:
- Validation: We will investigate and validate the vulnerability within 3 business days.
- Remediation: If validated, we aim to implement a security patch and release a fix within 7 business days.
- Disclosure: Once the fix is published, we will coordinate public disclosure and credit you for the find (unless you request to remain anonymous).