From a61e4f7f19de311285c6d919e1eff9d9bbb8c20c Mon Sep 17 00:00:00 2001 From: Dipanita45 <132455672+Dipanita45@users.noreply.github.com> Date: Tue, 13 Jan 2026 19:46:32 +0530 Subject: [PATCH 1/4] Added --- Security.md | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 Security.md diff --git a/Security.md b/Security.md new file mode 100644 index 0000000..8fec457 --- /dev/null +++ b/Security.md @@ -0,0 +1,25 @@ +Security Policy +Supported Versions +The following versions of Edulume are currently supported with security updates: + +Version Supported +1.x.x ✅ Supported +0.x.x ❌ Not supported +Reporting a Vulnerability +If you discover a security vulnerability in Edulume, we encourage you to report it as soon as possible. We will investigate all legitimate reports and do our best to quickly fix the issue. + +# How to Report +Please report vulnerabilities by emailing us at edulume@gmail.com. Include as much detail as possible to help us identify and fix the issue swiftly. +Do not share the vulnerability publicly until it has been addressed and a patch is available. +Security Updates +We will notify users via GitHub releases for any critical security updates. +Minor security patches will be included in regular updates as needed. + +# Security Best Practices +Make sure to use the latest version of Edulume for the latest security features and patches. +Follow password best practices, such as using strong, unique passwords for each account. +Regularly update your dependencies to the latest versions. + +# Acknowledgements +We appreciate contributions from the community and researchers who help us improve the security of Edulume. Thank you for keeping the platform secure for everyone! + From bd8a0e694ad1a614b602b70a28e7bdce3692c53e Mon Sep 17 00:00:00 2001 From: Dipanita45 <132455672+Dipanita45@users.noreply.github.com> Date: Thu, 15 Jan 2026 09:29:55 +0530 Subject: [PATCH 2/4] Update --- Security.md | 43 +++++++++++++++++++++++++++++++++++-------- 1 file changed, 35 insertions(+), 8 deletions(-) diff --git a/Security.md b/Security.md index 8fec457..51885a6 100644 --- a/Security.md +++ b/Security.md @@ -1,20 +1,47 @@ -Security Policy -Supported Versions +## Security Policy +## Supported Versions The following versions of Edulume are currently supported with security updates: -Version Supported -1.x.x ✅ Supported -0.x.x ❌ Not supported -Reporting a Vulnerability +## Supported Versions + +The following versions of Edulume are currently supported with security updates: +## Version Supported +1.x.x ✅ Yes +0.x.x ❌ No + +## Reporting a Vulnerability If you discover a security vulnerability in Edulume, we encourage you to report it as soon as possible. We will investigate all legitimate reports and do our best to quickly fix the issue. # How to Report -Please report vulnerabilities by emailing us at edulume@gmail.com. Include as much detail as possible to help us identify and fix the issue swiftly. +Please report vulnerabilities by emailing us at tarinagarwal@gmail.com. Include as much detail as possible to help us identify and fix the issue swiftly. Do not share the vulnerability publicly until it has been addressed and a patch is available. -Security Updates + +## Security Updates We will notify users via GitHub releases for any critical security updates. Minor security patches will be included in regular updates as needed. +## Response Timeline +We aim to follow this response process: +Initial acknowledgment: within 48 hours +Investigation and assessment: within 5–7 business days +Fix and patch release: as soon as reasonably possible, depending on severity + +## Scope of Security Concerns + +The following areas are considered in scope for security reports: + +Authentication and authorization mechanisms +API endpoints and backend services +User data handling and storage +File uploads and document storage +Access control and permission issues +Dependency-related vulnerabilities + +The following are out of scope: +Social engineering attacks +Physical attacks +Denial-of-service attacks without proof of concept + # Security Best Practices Make sure to use the latest version of Edulume for the latest security features and patches. Follow password best practices, such as using strong, unique passwords for each account. From a353020642d8ad989f9e1b0d9b6d04381c496dd3 Mon Sep 17 00:00:00 2001 From: Dipanita45 <132455672+Dipanita45@users.noreply.github.com> Date: Thu, 15 Jan 2026 20:04:06 +0530 Subject: [PATCH 3/4] Update --- Security.md | 12 +++++------- 1 file changed, 5 insertions(+), 7 deletions(-) diff --git a/Security.md b/Security.md index 51885a6..152d09e 100644 --- a/Security.md +++ b/Security.md @@ -1,18 +1,17 @@ ## Security Policy -## Supported Versions -The following versions of Edulume are currently supported with security updates: ## Supported Versions The following versions of Edulume are currently supported with security updates: -## Version Supported -1.x.x ✅ Yes -0.x.x ❌ No +| Version | Supported | +|---------|-----------| +| 1.x.x | Yes | +| 0.x.x | No | ## Reporting a Vulnerability If you discover a security vulnerability in Edulume, we encourage you to report it as soon as possible. We will investigate all legitimate reports and do our best to quickly fix the issue. -# How to Report +## How to Report Please report vulnerabilities by emailing us at tarinagarwal@gmail.com. Include as much detail as possible to help us identify and fix the issue swiftly. Do not share the vulnerability publicly until it has been addressed and a patch is available. @@ -49,4 +48,3 @@ Regularly update your dependencies to the latest versions. # Acknowledgements We appreciate contributions from the community and researchers who help us improve the security of Edulume. Thank you for keeping the platform secure for everyone! - From 31f1bb30900820c19e5cd2fcd645852bb23ea623 Mon Sep 17 00:00:00 2001 From: Dipanita45 <132455672+Dipanita45@users.noreply.github.com> Date: Sat, 17 Jan 2026 10:55:04 +0530 Subject: [PATCH 4/4] Update --- Security.md | 51 +++++++++++++++++++++++++++++++-------------------- 1 file changed, 31 insertions(+), 20 deletions(-) diff --git a/Security.md b/Security.md index 152d09e..c395120 100644 --- a/Security.md +++ b/Security.md @@ -3,48 +3,59 @@ ## Supported Versions The following versions of Edulume are currently supported with security updates: + | Version | Supported | |---------|-----------| -| 1.x.x | Yes | -| 0.x.x | No | +| 1.x.x | Yes | +| 0.x.x | No | ## Reporting a Vulnerability + If you discover a security vulnerability in Edulume, we encourage you to report it as soon as possible. We will investigate all legitimate reports and do our best to quickly fix the issue. ## How to Report + Please report vulnerabilities by emailing us at tarinagarwal@gmail.com. Include as much detail as possible to help us identify and fix the issue swiftly. + Do not share the vulnerability publicly until it has been addressed and a patch is available. ## Security Updates -We will notify users via GitHub releases for any critical security updates. + +We will notify users via GitHub releases for any critical security updates. Minor security patches will be included in regular updates as needed. ## Response Timeline + We aim to follow this response process: -Initial acknowledgment: within 48 hours -Investigation and assessment: within 5–7 business days -Fix and patch release: as soon as reasonably possible, depending on severity + +- Initial acknowledgment: within 48 hours +- Investigation and assessment: within 5–7 business days +- Fix and patch release: as soon as reasonably possible, depending on severity ## Scope of Security Concerns The following areas are considered in scope for security reports: -Authentication and authorization mechanisms -API endpoints and backend services -User data handling and storage -File uploads and document storage -Access control and permission issues -Dependency-related vulnerabilities +- Authentication and authorization mechanisms +- API endpoints and backend services +- User data handling and storage +- File uploads and document storage +- Access control and permission issues +- Dependency-related vulnerabilities The following are out of scope: -Social engineering attacks -Physical attacks -Denial-of-service attacks without proof of concept -# Security Best Practices -Make sure to use the latest version of Edulume for the latest security features and patches. -Follow password best practices, such as using strong, unique passwords for each account. -Regularly update your dependencies to the latest versions. +- Social engineering attacks +- Physical attacks +- Denial-of-service attacks without proof of concept + +## Security Best Practices + +- Make sure to use the latest version of Edulume for the latest security features and patches. +- Follow password best practices, such as using strong, unique passwords for each account. +- Regularly update your dependencies to the latest versions. + +## Acknowledgements -# Acknowledgements We appreciate contributions from the community and researchers who help us improve the security of Edulume. Thank you for keeping the platform secure for everyone! +