Found a security issue on this site? Thank you for taking the time to report it.
How to report
Email [email protected] with:
- the affected URL or component,
- what you found and why it matters,
- steps to reproduce (a short proof of concept helps),
- whether and how you would like to be credited.
I aim to acknowledge reports within 5 working days and to keep you updated until the issue is resolved. This is a personal site, so responses are best effort.
Scope
In scope: christoskalyvas.eu and www.christoskalyvas.eu, including the blog and the /profile/ pages.
Out of scope:
- third-party services this site links to or uses (such as GitHub, Cloudflare and social networks), which have their own programmes,
- denial-of-service, spam or social-engineering tests,
- reports from automated scanners without a demonstrated impact (for example, missing headers on a static site with no user input).
Disclosure
Please act in good faith: stay within scope, avoid privacy violations and service disruption, and give me reasonable time to fix the issue before disclosing it publicly.
There is no paid bug bounty.
Acknowledgments
Thank you to the people who have responsibly reported issues:
- Be the first.
Machine-readable version: /.well-known/security.txt (RFC 9116).