Skip to content

Security: mazino2d/mazino2d.github.io

.github/SECURITY.md

Security Policy

Supported Versions

This is a personal blog hosted on GitHub Pages. Security updates are applied to the latest version of the site.

Version Supported
Latest

Reporting a Vulnerability

If you discover a security vulnerability in this blog, please report it by:

  1. Email: Send details to [mazino2d@gmail.com]
  2. GitHub: Open a private security advisory in this repository

What to Include

Please include the following information in your report:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Any suggested fixes (if applicable)

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Varies based on severity and complexity

Security Best Practices

This blog follows these security practices:

  • Regular dependency updates
  • Secure Jekyll configuration
  • HTTPS enforcement via GitHub Pages
  • Content Security Policy headers (where applicable)
  • No storage of sensitive user data

Security Considerations

This blog uses:

  • Jekyll: Static site generator
  • Beautiful Jekyll: Theme framework
  • Third-party Services: Comments (Disqus, Giscus, Utterances), Analytics (Google Analytics, Cloudflare Analytics)

Third-Party Dependencies

All third-party scripts and services are loaded from trusted sources. Regular audits are performed to ensure:

  • Dependencies are up-to-date
  • No known vulnerabilities exist
  • Privacy policies are respected

Scope

This security policy covers:

  • The static site generator configuration
  • Custom JavaScript and CSS
  • Third-party integrations (comments, analytics)
  • Build and deployment process

Out of Scope

  • GitHub Pages infrastructure (managed by GitHub)
  • Third-party services (Disqus, Google Analytics, etc.)
  • User-generated content in comments

Privacy

This blog may use analytics and commenting services. Please refer to the privacy policy (if available) for information on data collection and usage.

Thank you for helping keep this blog secure!

There aren’t any published security advisories