Skip to content

Security: boredchilada/clickfix-simulator-2025

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
1.0.x ✅
< 1.0 ❌

Reporting a Vulnerability

We take the security of this tool seriously. If you believe you have found a security vulnerability in the ClickFix Training Tool, please report it to us as described below.

DO NOT open an issue on GitHub for security vulnerabilities.

How to Report

Please report security vulnerabilities through GitHub Security Advisories or by opening a private security issue.

Please include the following details in your report:

  • Type of issue (e.g., XSS, SQL Injection, RCE)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Response

We will acknowledge receipt of your report within 48 hours and will provide an estimated timeline for addressing the issue. We will keep you informed of our progress.

Disclosure Policy

We ask that you do not disclose the vulnerability to the public until we have had a chance to fix it. We will work with you to coordinate the public disclosure of the vulnerability.

There aren't any published security advisories