Security Policy
Thank you for helping keep SmartGen Docs secure. We appreciate responsible security research and encourage the community to report potential vulnerabilities privately so they can be investigated and resolved before public disclosure.
Supported Versions
The following versions currently receive security updates:
| Version | Supported |
|---|---|
| Latest Stable | ✅ Yes |
Development (main) |
✅ Yes |
| Older Releases | ❌ No |
Reporting a Vulnerability
If you discover a security vulnerability, please do not create a public GitHub issue.
Instead, report it privately by email.
Security Contact
Email: info@sayadbayezid.com
Please include as much information as possible:
- A clear description of the vulnerability
- Steps to reproduce the issue
- A proof of concept (if applicable)
- Potential security impact
- Suggested mitigation or fix (optional)
- Screenshots, logs, or supporting files (if available)
Providing detailed information helps us investigate and resolve issues more quickly.
Response Timeline
We aim to respond according to the following timeline:
| Stage | Target Time |
|---|---|
| Initial acknowledgement | Within 72 hours |
| Initial investigation | Within 7 days |
| Status update | As needed |
| Security fix | Depending on severity |
Complex vulnerabilities may require additional time for investigation and testing.
Coordinated Disclosure
We support responsible disclosure.
Please allow us reasonable time to investigate and release a fix before publicly disclosing any security vulnerability.
Once a fix has been released, we welcome coordinated public disclosure and will gladly acknowledge responsible researchers (unless anonymity is requested).
Scope
This security policy applies to the official SmartGen Docs project, including:
- Core framework
- Documentation generator
- CLI
- Theme system
- Templates
- Static site builder
- Development server
- Official GitHub repository
Repository:
https://github.com/bayeziddev/smartGenDocs
Out of Scope
The following generally fall outside this policy:
- Third-party libraries
- Issues in external dependencies
- Social engineering attacks
- Spam reports
- Denial-of-Service testing
- Vulnerabilities requiring physical device access
- Issues requiring unrealistic attack scenarios
Best Practices
If you believe you've discovered a vulnerability, please:
- Do not publicly disclose the issue before a fix is available.
- Avoid accessing or modifying data that does not belong to you.
- Do not disrupt services or other users.
- Only perform testing necessary to verify the issue.
- Respect the privacy and security of all users.
Security Updates
Security fixes may be released independently of normal feature updates.
Important fixes will be documented in:
- CHANGELOG.md
- GitHub Releases
- Project Documentation
Supported Communication
For security-related questions or vulnerability reports:
Email: info@sayadbayezid.com
General project discussions and feature requests should be submitted through GitHub Issues.
Acknowledgements
We sincerely appreciate responsible security researchers and community members who help improve the security, stability, and reliability of SmartGen Docs through coordinated vulnerability disclosure.
Thank you for helping make SmartGen Docs safer for everyone.