Security Policy
This repository hosts a static personal website (resume, portfolio, hobbies) with no server-side code, database, or user input handling — the attack surface is intentionally minimal.
Reporting a Vulnerability
If you find a security issue with this site (e.g., a misconfigured header, exposed sensitive data, or a supply-chain concern with a dependency), please open a private report via GitHub’s security advisory form or email iam@calvinwong.ca.
Scope
- No secrets, credentials, or personal data beyond publicly-intended contact details are stored in this repository.
- Dependabot alerts are enabled to flag known vulnerabilities in any future build dependencies.