Skip to content

Security: thexsa/HeaderQuarters

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

We take the security of HeaderQuarters very seriously. If you discover a security vulnerability, we ask that you report it to us privately so we can address it before it's publicly disclosed.

Please do not report security vulnerabilities through public GitHub issues.

Instead, please send an email to: Security@thexholdings.com

What to include in your report:

  • A descriptive summary of the vulnerability.
  • Detailed reproduction steps.
  • The perceived impact of the vulnerability.
  • CRITICAL: Do NOT include any active secrets, API keys, or personal tokens in your reports or reproduction steps. Use dummy values.

Expected Response

  • We will acknowledge receipt of your vulnerability report within 48 hours.
  • We aim to triage and provide a fix or mitigation plan within 30 days.

Scope

In Scope:

  • HeaderQuarters extension source code
  • Build system configuration (Vite, Rollup)
  • Project dependencies (if exploitable through the extension)

Out of Scope:

  • Chrome browser bugs or inherent declarativeNetRequest limitations.
  • Issues requiring enterprise policies or MDM to exploit.
  • Physical access to an unlocked device.

There aren't any published security advisories