diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..90d9f98 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,81 @@ +# ๐Ÿ” Security Policy + +## ๐Ÿ“ฆ Project: [checkcle](https://github.com/operacle/checkcle) + +**checkcle** is a lightweight, TypeScript-based built for uptime and server monitoring tools. + +We care about the security and privacy of users running this project in production environments. + +--- + +## ๐Ÿ“ฃ Reporting a Vulnerability + +If you believe you have found a security vulnerability in this project: + +- **DO NOT** open a public issue to report it. +- Please report it responsibly via one of the following methods: + +### ๐Ÿ” Preferred: [Report a Vulnerability via GitHub](https://github.com/operacle/checkcle/security/advisories/new) + +- Use the GitHub security advisory form (private and secure). +- Attach as much detail as possible: + - Description of the issue + - Affected version or commit hash + - Reproduction steps + - Impact and any potential mitigations + - Logs or screenshots (if available) + +### ๐Ÿ“ง Alternatively: Contact the Maintainer +- Email: `security@checkcle.io` +- Optionally include a PGP public key for encrypted messages + +We aim to respond within **3โ€“5 business days**. + +--- + +## โœ… Supported Versions + +We support the latest stable release of `checkcle`. Security patches may also be applied to recent versions at our discretion. + +| Version | Supported | +|---------|-----------| +| `main` (latest) | โœ… Yes | +| Older versions | โš ๏ธ Best-effort | +| Pre-release or forks | โŒ No | + +--- + +## ๐Ÿ” Security Practices + +This project adheres to the following practices to enhance security: + +- ๐Ÿ”Ž Regular vulnerability checks using `npm audit` +- โ›“๏ธ Dependency pinning via `package-lock.json` +- โœ… Type-safe code using `TypeScript` +- ๐Ÿงช Continuous testing and CI +- ๐Ÿ” No data is stored or transmitted unless explicitly configured by the user +- ๐Ÿง‘โ€๐Ÿ’ป All contributions are reviewed before being merged + +--- + +## โš ๏ธ Known Security Limitations + +- `checkcle` makes outbound HTTPS requests to check certificate details โ€” avoid running in untrusted or high-risk environments without proper network policies. +- Output may contain certificate metadata (e.g., CN, SANs, expiry dates) โ€” avoid exposing this to public logs unless sanitized. +- The data may be lost upon system restarts or crashes. Always ensure that backup and recovery mechanisms are in place in production environments. + +--- + +## ๐Ÿ“„ License + +This project is released under the [MIT License](./LICENSE). Use at your own risk. The Creator and contributors are not liable for misuse, data loss, or operational impact resulting from use of the software. + +--- + +## ๐Ÿ™Œ Acknowledgements + +We appreciate responsible disclosures from the community. Your efforts help us make the open-source ecosystem safer for everyone. + +Thanks & Regards, + +โ€” [Tola Leng](https://github.com/tolaleng)