This project is a static website and we maintain security for the following:
| Component | Version | Supported |
|---|---|---|
| Website | Latest | ✅ |
| Dependencies | Latest | ✅ |
We take security seriously. If you discover a security vulnerability in our Aurora Zone website, please help us by reporting it responsibly.
- DO NOT create a public GitHub issue for security vulnerabilities
- Send an email to the maintainer with details about the vulnerability
- Include the following information:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if you have one)
- Acknowledgment: We'll acknowledge receipt of your report within 48 hours
- Investigation: We'll investigate and validate the report within 7 days
- Resolution: We'll work to resolve valid security issues as quickly as possible
- Credit: We'll give you credit for the discovery (if you wish)
This website follows these security practices:
- HTTPS Only: All connections should use HTTPS
- Content Security Policy: Implemented to prevent XSS attacks
- No Sensitive Data: We don't store or process sensitive user data
- Regular Updates: Dependencies and code are regularly reviewed
- Input Validation: All user inputs are properly validated and sanitized
Security reports are welcomed for:
- Cross-site scripting (XSS)
- Content injection
- Authentication/authorization flaws
- Configuration issues
- Dependency vulnerabilities
- Issues in third-party services (Dawn, GitHub Pages)
- Social engineering attacks
- Physical attacks
- Denial of service attacks
- Issues that require physical access to user devices
For security-related questions or to report vulnerabilities, please contact:
- GitHub: @TurboRx
- Create a private security advisory on this repository
Thank you for helping keep Aurora Zone safe!