| Version | Supported |
|---|---|
| 1.x (Current) | ✅ |
| < 1.0 | ❌ |
The Alumni-Management-System handles manage alumni connections, events, job postings, and foster community engagement. We take security vulnerabilities seriously.
Please do NOT open a public GitHub issue for security vulnerabilities.
Instead, report privately via:
- Email: https://www.omkarhole.xyz/
- GitHub Private Advisory: Go to the Security tab → Click "Report a vulnerability"
- Description of the vulnerability
- Steps to reproduce
- Potential impact (especially on credit/financial data)
- Suggested fix (optional)
| Action | Timeframe |
|---|---|
| Acknowledgement | Within 48 hours |
| Status Update | Within 5 business days |
| Fix / Resolution | Within 30 days |
- All PRs are reviewed by the maintainer before merging
- No sensitive data (API keys, credentials) is hardcoded
- ML models handle financial data — inputs are validated and scaled before processing
- Dependencies (npm - Package management 🔄 Nodemon - Development auto-restart 🔍 ESLint - Code linting 📝 Prettier - Code formatting, etc.) are periodically reviewed
- Contributors must follow our Code of Conduct
Once a vulnerability is resolved:
- A patched version will be released
- Reporter will be credited (if they wish)
- A brief summary of the fix will be shared
Omkar — Project Maintainer & NSoC'26 Admin