Skip to content

Security: dharnak/Resume-Generator

Security

SECURITY.md

Security Policy

Supported Versions

We take security seriously. The following versions of Resume Generator are currently supported with security updates:

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability in Resume Generator, please help us by reporting it responsibly.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by emailing the maintainers at security@resume-generator.dev or by creating a private security advisory on GitHub.

What to Include

When reporting a security vulnerability, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggested fixes or mitigations

Our Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours
  2. Investigation: We will investigate the issue and determine its severity
  3. Updates: We will provide regular updates on our progress
  4. Fix: We will work on a fix for confirmed vulnerabilities
  5. Disclosure: We will coordinate disclosure with you

Security Best Practices

Resume Generator is designed with security in mind:

  • Client-side only: All processing happens in your browser - your resume data never leaves your device
  • No external dependencies for core functionality
  • No data collection: We don't collect or store any personal information
  • Open source: Code is publicly auditable

Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Avoid accessing or modifying user data
  • Don't perform DoS attacks or degrade service performance
  • Don't spam our systems with automated vulnerability scanners

Contact

For security-related questions or concerns, please contact the maintainers through the channels mentioned above.

Thank you for helping keep Resume Generator secure! 🛡️

There aren’t any published security advisories