Skip to content

Security: chirag127/DevRead-Curated-Programming-Book-Awesome-List

.github/SECURITY.md

🛡️ DevRead: Security Policy and Responsible Disclosure

The DevRead-Curated-Programming-Book-Awesome-List repository is maintained by the Apex Technical Authority and focuses on providing a secure, reliable, and high-integrity list of educational resources. While this repository is primarily composed of static Markdown and external links, we treat link integrity and content safety as critical security concerns.

1. Vulnerability Disclosure Policy

We request that any potential security issues related to the integrity of the content—specifically, malicious, compromised, or unethical links within the list—be reported privately before public discussion.

Private Reporting

Please report content security vulnerabilities and link integrity issues by emailing the core maintenance team directly:

📧 Email: [email protected] Subject Line: [DevRead Security Alert] - Urgent Link Integrity Issue

We commit to the following response timeline:

  1. Acknowledgement: We will acknowledge receipt of your report within 48 hours.
  2. Assessment and Remediation Plan: We will provide an initial assessment and an expected remediation timeline within 5 business days.
  3. Resolution: Critical links found to be compromised will be removed immediately or replaced with a safe alternative.

Please include the following details in your report:

  1. The specific file, section, and the compromised URL.
  2. Description of the risk (e.g., phishing, malware, violation of ethical sourcing).
  3. Steps required to verify the malicious activity.

2. Scope and Policy Focus

Given the nature of this project as a static 'Awesome List,' our security focus is centered on ensuring the trustworthiness of all external resources.

In Scope:

  • Links pointing to known malicious domains, malware distribution, or phishing sites.
  • Links that violate the project's core ethical mandate (e.g., promoting illegal content distribution).
  • Vulnerabilities in GitHub repository configuration or GitHub Actions workflows (CI/CD supply chain risks, though minimal).

Out of Scope:

  • Vulnerabilities in the external websites linked by the list (these must be reported to the respective domain owners).
  • General formatting errors, typographical errors, or outdated non-critical information (please use standard GitHub Issues or Pull Requests for these).

3. Maintaining Integrity

All contributions adding new links are subject to rigorous automated scanning and mandatory manual review by maintainers to uphold the quality and safety standards of the DevRead resource list.

There aren’t any published security advisories