Skip to content

Security: RitualDev-Lab/DevShelf

SECURITY.md

Security Policy

The DevShelf maintainer team takes the security and integrity of our codebase, interactive web directory, and community submissions very seriously.

Supported Versions

We actively maintain and provide security patches for the following versions:

Version Supported
1.x.x
< 1.0.0

Reporting a Vulnerability

If you discover a security vulnerability in DevShelf (including our automated scripts, GitHub Actions workflows, web application frontend, or dependency chain):

  1. Do NOT open a public GitHub issue. Public issues disclose potential attack vectors before a fix can be prepared.
  2. Use GitHub Private Vulnerability Reporting:
    • Navigate to the Security tab on GitHub.
    • Click "Report a vulnerability" to submit an advisory privately to the maintainers.
  3. Alternative Direct Email:
    • If GitHub private reporting is unavailable, email our security team directly at: security@ritualdev.com
    • Please include:
      • Description of the vulnerability and affected components.
      • Proof of Concept (PoC) or reproduction steps.
      • Potential impact on users or directory integrity.

Response SLA

  • Initial Response: Within 24-48 hours of receipt.
  • Triage & Status Update: Within 72 hours.
  • Fix & Disclosure: Coordinated disclosure after patch verification and deployment.

Content & Malicious Resource Reporting Policy

DevShelf is a crowdsourced repository. We enforce strict policies to protect developers:

  • Zero Tolerance for Malware / Phishing: If any curated link or project distributes malware, spyware, unauthorized telemetry, or phishing pages, administrators will remove it immediately upon verification.
  • Deceptive Paywalls & Bait-and-Switch: Tools submitted as "100% Free" that secretly require payment or credit cards to use core features will be delisted.
  • Reporting Inappropriate Content:
    • Anyone in the developer community can report problematic entries using our Content Report Template.
    • Repository administrators actively review all incoming content reports.

Thank you for keeping the open-source community safe! ???

There aren't any published security advisories