Skip to content

Security: dat-angel/openpinas

Security

SECURITY.md

Security Policy

Supported Versions

We actively support the latest version of OpenPinas. Security updates are applied to the main branch.

Version Supported
Latest
< Latest

Reporting a Vulnerability

If you discover a security vulnerability in OpenPinas, please do not open a public issue.

Instead, please report it via one of the following methods:

  1. Private Security Advisory: Create a private security advisory on GitHub (preferred)
  2. Direct Message: Contact @dat-angel on GitHub

What to Include

When reporting a security vulnerability, please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)
  • Your contact information (if you'd like to be credited)

Response Time

We aim to:

  • Acknowledge receipt within 48 hours
  • Provide initial assessment within 7 days
  • Provide update on resolution timeline within 14 days

Security Considerations

Data Security

This project contains public information only:

  • Political dynasty data (public records)
  • News events (publicly reported)
  • Corruption cases (public records)

No private or sensitive personal information is stored in this repository.

Website Security

The website is hosted on GitHub Pages (static hosting). If you discover:

  • XSS vulnerabilities
  • Data injection issues
  • Authentication problems (if added in future)
  • Other security concerns

Please report them using the methods above.

Data Integrity

If you discover:

  • Malicious data in the repository
  • Data manipulation attempts
  • Source verification issues

Please report them immediately.

Best Practices

When contributing:

  • ✅ Only submit data from verified public sources
  • ✅ Include source URLs for all data
  • ✅ Validate JSON before submitting
  • ✅ Review your changes before committing
  • ❌ Never include private information
  • ❌ Never include unverified rumors
  • ❌ Never include potentially defamatory content without sources

Thank You

Thank you for helping keep OpenPinas secure! Security researchers and contributors who help identify and fix security issues are greatly appreciated.

There aren’t any published security advisories