Do not open a public issue.
If available, go to the Security tab of this repository → Report a vulnerability to submit a private report.
Private reporting availability has not been verified, and no alternative private contact is published. If the reporting button is absent, do not post vulnerability details in an issue, pull request or branch.
Acknowledgement commitment: within 24 hours of receipt through the private reporting channel.
- What you found
- How to reproduce it
- What it affects, and what an attacker could do with it
We will publish an advisory after remediation and credit you, unless you prefer otherwise.
In scope: this repository, and the portal at https://pmdevcore.gov.np/ once deployed.
Out of scope: other government systems — each has its own disclosure path. Also out of scope: denial of service, social engineering, and automated scanner output without a demonstrated impact.
We will not pursue action against good-faith security research that:
- Respects the privacy of others — do not access, modify or retain data belonging to another person
- Avoids degrading the service
- Gives us reasonable time to remediate before public disclosure
If you are unsure whether something is in scope, ask first through the private reporting channel.
Never commit a secret. If you believe a credential has been exposed, report it privately and immediately — do not open an issue or a pull request describing it.
If you find a security problem while working on an unrelated issue, stop and report it privately. A public fix is a public disclosure.