This repository, BookmarkMind-AI-Bookmark-Categorization-Browser-Extension, is maintained with a strong commitment to security. We welcome and appreciate security research and responsible disclosure from the community.
If you find a security vulnerability, please follow these steps:
- DO NOT report it via public GitHub issues, discussions, or pull requests. This includes security-related information.
- DO NOT use the GitHub Security Advisory feature for initial reporting if you are unsure of the process.
- DO INSTEAD: Send a detailed report to the security team via email at security@chirag127.dev.
- Please use a clear and concise subject line, such as "Security Vulnerability Report - [Repository Name]".
- In your report, include as much of the following information as possible:
- The affected component or area of the repository.
- A detailed description of the vulnerability.
- Steps to reproduce the vulnerability.
- Any relevant code snippets or logs.
- Your suggested remediation or mitigation.
- We will acknowledge receipt of your report within 2 business days and will aim to provide an update on the status of the vulnerability within 7 business days.
We are committed to fixing security issues in the latest stable version of BookmarkMind-AI-Bookmark-Categorization-Browser-Extension. Older versions may not be actively monitored for security vulnerabilities.
- Code Audits: Regular internal code reviews focusing on security best practices.
- Dependency Scanning: Automated scans of dependencies for known vulnerabilities.
- Linting & Formatting: Utilization of tools like BiomeJS to enforce code quality and catch potential issues early.
- Testing: Comprehensive test suites using Vitest and Playwright to ensure code behaves as expected and to catch regressions.
- Secure Development Lifecycle: Integrating security considerations throughout the development process, from design to deployment.
- AI Security: Strict adherence to API usage policies for Gemini and Groq, input validation, and output sanitization when interacting with AI models.
We strive to address reported vulnerabilities promptly and transparently. Our general timeline is:
- Acknowledgement: Within 2 business days.
- Investigation & Patching: Aim for within 7 business days for common vulnerabilities. Complex issues may require more time.
- Public Disclosure: Coordinated with the reporter, typically after a fix is available and deployed.
Thank you for helping to keep BookmarkMind-AI-Bookmark-Categorization-Browser-Extension secure!