| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in this portfolio website, please report it responsibly.
- Do NOT create a public GitHub issue for security vulnerabilities
- Email security concerns directly to: ian@allowayllc.com
- Include the following in your report:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Response Time: You will receive an acknowledgment within 48 hours
- Updates: We will provide status updates every 5 business days
- Resolution: Critical vulnerabilities will be addressed within 7 days
- Credit: Security researchers will be credited (unless anonymity is requested)
This is a static portfolio website. Security considerations include:
- XSS Prevention: All user-generated content is sanitized
- HTTPS: Site is served over HTTPS only
- Content Security Policy: CSP headers are configured
- External Links: External links use
rel="noopener noreferrer"
- Vercel/Netlify: Hosting platform security
- RSS Feed: External RSS service for blog posts
- Analytics: Google Analytics (if enabled)
- Keep dependencies updated
- Run
npm auditregularly - Review third-party scripts before inclusion
- Validate all external data sources
- Use environment variables for sensitive config
We follow responsible disclosure practices:
- Reporter notifies us of vulnerability
- We acknowledge and begin investigation
- We develop and test a fix
- We release the fix and notify users
- After 90 days (or upon fix release), details may be published
- Security Email: ian@allowayllc.com
- General Contact: @ianallowayxyz