Skip to content

Security: AlahmadiQ8/hr-evaluation

SECURITY.md

Security Policy

Scope

Taqyeem is a demonstration/sample application. All employees, names, org units, and scores are fictional and generated for demo purposes only — there is no real personal or production data in this repository.

Even so, we take the security of the code seriously and welcome reports of vulnerabilities (e.g. in the auth flows, API surface, dependencies, or CI/CD configuration).

Supported versions

This is a rolling demo: only the latest commit on main is supported. Fixes land on main.

Reporting a vulnerability

Please do not open a public issue for security problems.

Instead, report privately through GitHub's Private Vulnerability Reporting:

  1. Go to the repository's Security tab → Report a vulnerability.
  2. Describe the issue, affected component, and steps to reproduce.
  3. Include impact and any suggested remediation if you have one.

We aim to acknowledge reports within a few business days and will coordinate a fix and disclosure timeline with you. Because this is a sample project maintained on a best-effort basis, response times may vary.

Thanks

Responsible disclosure helps keep this sample — and anyone learning from it — safe. Thank you for taking the time to report.

There aren't any published security advisories