Skip to content

Security: SDOC-Team/devnepal

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue.

GitHub private vulnerability reporting

If available, go to the Security tab of this repository → Report a vulnerability to submit a private report.

Private reporting availability has not been verified, and no alternative private contact is published. If the reporting button is absent, do not post vulnerability details in an issue, pull request or branch.

Acknowledgement commitment: within 24 hours of receipt through the private reporting channel.

What to include

  • What you found
  • How to reproduce it
  • What it affects, and what an attacker could do with it

We will publish an advisory after remediation and credit you, unless you prefer otherwise.


Scope

In scope: this repository, and the portal at https://pmdevcore.gov.np/ once deployed.

Out of scope: other government systems — each has its own disclosure path. Also out of scope: denial of service, social engineering, and automated scanner output without a demonstrated impact.


Safe harbour

We will not pursue action against good-faith security research that:

  • Respects the privacy of others — do not access, modify or retain data belonging to another person
  • Avoids degrading the service
  • Gives us reasonable time to remediate before public disclosure

If you are unsure whether something is in scope, ask first through the private reporting channel.


For contributors

Never commit a secret. If you believe a credential has been exposed, report it privately and immediately — do not open an issue or a pull request describing it.

If you find a security problem while working on an unrelated issue, stop and report it privately. A public fix is a public disclosure.

There aren't any published security advisories