Security Policy

Security Policy

Reporting a vulnerability or accidental disclosure

Please do not open a public issue for a security vulnerability, exposed credential, or accidentally published sensitive information.

Use GitHub’s private vulnerability reporting. If that channel is unavailable, contact the repository owner through the public contact address on zhejianwang.com.

Include only the minimum information needed to identify the problem. Do not copy a discovered secret or sensitive record into an issue, pull request, discussion, or other public channel.

If a credential is exposed

Revoke or rotate the credential first. Removing it from the latest commit is not sufficient because Git history, forks, caches, and clones may retain earlier content.

Repository boundary

This is a public academic website repository. It is not an approved location for credentials, restricted research data, human-subject data, student records, private correspondence, personal records, or unpublished coauthor material without consent.

The automated public-content guard and GitHub Secret Scanning reduce accidental disclosure risk but do not replace human review.

Non-security corrections

Corrections to public biographical, research, publication, or teaching information may be reported through an ordinary issue. Do not include non-public supporting documents.