Skip to content

Security: ER723/detection-as-code

SECURITY.md

Security Policy

This is a personal portfolio project. There's no formal bug bounty or dedicated security team, but responsible disclosure is genuinely welcome.

Reporting a vulnerability

If you find a security issue in this repository — the code, the CI configuration, or anything else — please open a GitHub issue describing it, or reach out directly at asukmana723@gmail.com if it's sensitive enough that you'd rather not post it publicly first.

Please include:

  • What you found and where
  • Steps to reproduce, if applicable
  • Any suggested fix, if you have one

I'll acknowledge reports within a few days and aim to address genuine issues promptly.

Scope

This repository is documentation and a small test/detection-engineering harness — there's no production system, user data, or live service exposed through this code itself. Findings related to the underlying live pipeline (a private, separate system) can still be reported the same way.

There aren't any published security advisories