Skip to content

Security: Bus-Army-Dude/rivers-portfolio

Security

SECURITY.md

Security Policy

Security Features

1. Enhanced Copy Protection

  • Context menu prevention
  • Text selection prevention
  • Copy prevention
  • Drag-and-drop prevention for images and content
  • Media controls prevention

2. Content Security

  • User-generated content restrictions
  • Protected profile images
  • Secure external links (using target="_blank")
  • Image drag protection
  • Media controls disabled for video content

3. Device Information Security

  • Secure device detection system
  • Operating system version detection
  • Platform-specific security measures
  • Privacy-focused device information handling

4. Data Protection

  • Local storage encryption for theme preferences
  • Secure time and date handling
  • Protected user information
  • Secured countdown mechanisms

5. User Interface Security

  • Protected theme toggle functionality
  • Secure CSS variables
  • Protected class names
  • Secure DOM manipulation

6. Profile Security

  • Protected creator information
  • Secure social links
  • Protected follower counts
  • Verified badge protection

7. Event Security

  • Secure event modal functionality
  • Event details protection to prevent unauthorized access
  • Highlighting current day securely based on the user’s timezone

8. Theme and UI Consistency

  • Consistent styling and theming across all sections for improved security against UI manipulation
  • Protected layout components to prevent unauthorized alteration

9. Event Interaction Security

  • Prevent unauthorized interaction with event calendar details
  • Protected event data and indicators from tampering

10. Light/Dark Mode Security

  • Secure implementation of the light/dark mode toggle to prevent unauthorized changes

11. Font Size Adjustment Security

  • Secure handling of font size adjustments to prevent unauthorized changes

Reporting a Vulnerability

To report a security vulnerability, please follow these steps:

  1. DO NOT create a public GitHub issue for security vulnerabilities
  2. Create a private security advisory on GitHub
  3. Include the following information:
    • Type of vulnerability
    • Location of the vulnerability
    • Steps to reproduce
    • Potential impact

Security Updates

  • The website undergoes regular security updates
  • Security patches are implemented as soon as vulnerabilities are discovered
  • Users are notified of significant security updates through the version info section
  • Current stable version is v1.16.0

Security Best Practices

  1. For Users:

    • Keep your browser updated
    • Use secure and up-to-date operating systems
    • Report any suspicious activity
    • Do not attempt to circumvent security measures
    • Enable JavaScript, Location, and Cookies for features to work properly on the website.
    • For users accessing the website on TikTok, please follow these steps to access the weather feature:
      1. Tap the three dots in the right-hand corner of the TikTok app.
      2. Select "Open in Browser" to enable location access for the weather feature, as the TikTok browser prevents location detection.
  2. For Contributors:

    • Follow secure coding practices
    • Test security features before submitting changes
    • Keep dependencies updated
    • Review code for security vulnerabilities

Supported Versions

Version Supported
1.16.0
1.15.0
1.14.0
1.13.0
1.12.0
1.11.0
1.10.1
1.10.0
1.9.x
1.8.x
1.7.x
1.6.x
1.5.x
1.4.x
1.3.x
< 1.3

Security Contact

For any security-related concerns, please contact:

Repository Information

  • Repository: BusArmyDude/busarmydude
  • Language Composition:
    • JavaScript: 60.9%
    • CSS: 24.9%
    • HTML: 14.2%

Acknowledgments

We appreciate the security community's efforts in responsibly disclosing vulnerabilities and helping maintain the security of our website.

Version Control

This security policy is version 1.16.0 and was last updated on 2025-5-8 at 9:40 AM EST.


This document is maintained by @BusArmyDude

There aren’t any published security advisories