Skip to content

Security: luizbizzio/emojis

SECURITY.md

Security Policy

Scope

This repository is a documentation-only guide about emoji artwork licensing.

It does not contain emoji image assets, packaged software, backend services, authentication systems, payment flows, or production infrastructure. The repository content is Markdown text and links to external licensing sources.

Supported Versions

Security updates are handled on the latest version of the repository only.

Version Supported
Latest main branch Yes
Older commits, forks, or copied versions No

What to Report

Please report issues that could create a real security or trust risk, including:

  • Malicious or compromised links added to the guide
  • Links that redirect to phishing, malware, or impersonated vendor pages
  • Accidentally committed private data, credentials, tokens, or internal URLs
  • Files added to the repository that appear suspicious or executable
  • Incorrect security-sensitive guidance that could put users at risk

What Not to Report

The following are not considered security vulnerabilities in this repository:

  • Disagreements about emoji licensing interpretation
  • Requests for legal advice
  • A vendor changing its license after the guide was written
  • Missing emoji vendors or incomplete licensing coverage
  • Broken links that do not create a security risk
  • Copyright or trademark disputes

For licensing corrections, open a normal issue and include the official source.

Reporting a Vulnerability

If you find a security issue, please do not open a public issue with sensitive details.

Use one of these options:

  1. Open a private vulnerability report on GitHub, if available.
  2. Contact the maintainer directly through the contact information listed on the GitHub profile.

Please include:

  • A clear description of the issue
  • The affected file or link
  • Steps to verify the issue
  • Why it creates a security risk
  • Any safe suggested fix

Response Expectations

This is a small documentation repository maintained on a best-effort basis.

Valid security reports will be reviewed as soon as practical. If the issue is confirmed, the fix will normally be made by updating or removing the affected link, text, or file.

External Links and Third-Party Sources

This repository links to third-party emoji projects, vendor pages, and license texts.

Users should always verify important licensing or security-sensitive information directly from the official source before using emoji assets in a product. This repository is an informational guide, not a legal or security guarantee.

Maintainer Notes

Security issues in this repository are mostly trust and supply-chain issues, not application vulnerabilities.

The most important risks are malicious links, misleading source references, and accidentally committed sensitive data.

There aren't any published security advisories