Skip to content

Security: S4mu3lD4v1d/kindpath-starter

Security

SECURITY.md

Security Policy — KindPath Collective

We take security seriously, especially where systems touch community wellbeing, sensitive context, or governance workflows.

Supported scope

This policy applies to:

  • Code and tooling in KindPath repositories
  • Website deployments and public infrastructure (where applicable)
  • Configuration issues that expose secrets, credentials, or private data

Please do NOT

  • Open a public Issue for vulnerabilities that could be exploited
  • Post credentials, API keys, tokens, or private data in public threads

How to report a vulnerability

Email:

Include:

  • Where the issue is (repo + file/path + version/commit if possible)
  • Impact (what could happen if exploited)
  • Reproduction steps (proof-of-concept if safe)
  • Any suggested mitigation or patch ideas (optional)

What happens next

We will:

  • Acknowledge receipt
  • Assess severity and scope
  • Coordinate a fix and a responsible disclosure plan

Responsible disclosure

Please give us a reasonable window to investigate and patch before public disclosure. If you believe users are at immediate risk, say so clearly in your report.

Thanks

If you report responsibly, you’re helping protect people — and we appreciate it.

There aren’t any published security advisories