Security Policy

Thank you for helping keep SmartGen Docs secure. We appreciate responsible security research and encourage the community to report potential vulnerabilities privately so they can be investigated and resolved before public disclosure.


Supported Versions

The following versions currently receive security updates:

Version Supported
Latest Stable ✅ Yes
Development (main) ✅ Yes
Older Releases ❌ No

Reporting a Vulnerability

If you discover a security vulnerability, please do not create a public GitHub issue.

Instead, report it privately by email.

Security Contact

Email: info@sayadbayezid.com

Please include as much information as possible:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • A proof of concept (if applicable)
  • Potential security impact
  • Suggested mitigation or fix (optional)
  • Screenshots, logs, or supporting files (if available)

Providing detailed information helps us investigate and resolve issues more quickly.


Response Timeline

We aim to respond according to the following timeline:

Stage Target Time
Initial acknowledgement Within 72 hours
Initial investigation Within 7 days
Status update As needed
Security fix Depending on severity

Complex vulnerabilities may require additional time for investigation and testing.


Coordinated Disclosure

We support responsible disclosure.

Please allow us reasonable time to investigate and release a fix before publicly disclosing any security vulnerability.

Once a fix has been released, we welcome coordinated public disclosure and will gladly acknowledge responsible researchers (unless anonymity is requested).


Scope

This security policy applies to the official SmartGen Docs project, including:

  • Core framework
  • Documentation generator
  • CLI
  • Theme system
  • Templates
  • Static site builder
  • Development server
  • Official GitHub repository

Repository:

https://github.com/bayeziddev/smartGenDocs


Out of Scope

The following generally fall outside this policy:

  • Third-party libraries
  • Issues in external dependencies
  • Social engineering attacks
  • Spam reports
  • Denial-of-Service testing
  • Vulnerabilities requiring physical device access
  • Issues requiring unrealistic attack scenarios

Best Practices

If you believe you've discovered a vulnerability, please:

  • Do not publicly disclose the issue before a fix is available.
  • Avoid accessing or modifying data that does not belong to you.
  • Do not disrupt services or other users.
  • Only perform testing necessary to verify the issue.
  • Respect the privacy and security of all users.

Security Updates

Security fixes may be released independently of normal feature updates.

Important fixes will be documented in:

  • CHANGELOG.md
  • GitHub Releases
  • Project Documentation

Supported Communication

For security-related questions or vulnerability reports:

Email: info@sayadbayezid.com

General project discussions and feature requests should be submitted through GitHub Issues.


Acknowledgements

We sincerely appreciate responsible security researchers and community members who help improve the security, stability, and reliability of SmartGen Docs through coordinated vulnerability disclosure.

Thank you for helping make SmartGen Docs safer for everyone.