This policy provides a private route for reporting credentials, personal or confidential information, unsafe publication, malicious repository behavior, or another security-sensitive condition affecting this repository.
It does not replace the Code of Conduct, contribution process, or appropriate professional and organizational incident-response procedures.
The latest approved release and the current main branch receive
security-sensitive corrections. Superseded versions may be corrected when the
founding steward determines that the consequence warrants it.
Do not place credentials, personal information, private evidence, exploit instructions, confidential sources, or sensitive relationship details in a public issue, pull request, discussion, or appeal.
Use
GitHub private vulnerability reporting.
If it is unavailable, use a private contact route listed on the
@BradGroux GitHub profile.
If neither route is immediately available, submit the private sensitive-disclosure contact request without credentials, names, evidence, contact details, exploit instructions, or other sensitive information. The public request is not a private reporting channel. Retain the sensitive material safely until a private route is established.
Include only what is necessary to establish:
- the affected repository content or release;
- the nature and likely consequence of the condition;
- whether sensitive material may already be public;
- safe reproduction or verification steps, when applicable;
- containment already performed; and
- a private way to continue the report.
The founding steward or delegated maintainer will:
- acknowledge and contain the report through a private channel;
- preserve necessary evidence without unnecessarily copying sensitive material;
- assess affected content, versions, derivatives, and recipients;
- involve the appropriate privacy, security, legal, records, safety, or other authority when needed;
- correct, withdraw, rotate, or otherwise contain affected material;
- verify the correction and document the release effect; and
- coordinate any public disclosure so it does not increase harm.
No response-time guarantee, bug bounty, confidentiality contract, or safe-harbor term is created by this policy. The framework itself is not a security control, privacy program, legal opinion, or certification for an implementation.