Skip to content

Security: manmeetnain/storagecraft

SECURITY.md

Security Policy

StorageCraft is primarily educational software, but security and privacy defects still matter.

Please do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting with the affected path, reproduction steps, impact, and any suggested mitigation. You should receive an acknowledgement within 72 hours.

Never include credentials, customer data, proprietary configurations, or sensitive infrastructure details in a report or example.

Security fixes are applied to the latest release and the main branch. Relevant reports include unsafe educational guidance, code execution, dependency or workflow compromise, credential exposure, prompt injection, and examples that could cause destructive infrastructure operations when followed without appropriate safeguards.

Only test systems and data you own or are explicitly authorized to assess. Reports involving a third-party product should also be submitted to that vendor through its security process.

There aren't any published security advisories