Skip to content

Security: blaquebaux/brown

SECURITY.md

Security policy

BLAQUE BAUX publishes research software, analytical tools, and governed execution infrastructure. We take reports involving credentials, unsafe execution paths, dependency compromise, data leakage, or material integrity failures seriously.

Reporting a vulnerability

Please do not open a public issue for a suspected security vulnerability.

Use the affected repository's Security tab and select Report a vulnerability. Include:

  • the affected repository, version, or commit;
  • a concise description of the issue and its impact;
  • reproducible steps or a minimal proof of concept;
  • any suggested mitigation; and
  • whether the report may be acknowledged publicly after resolution.

We will acknowledge a complete report as soon as practical, investigate it privately, and coordinate disclosure when a fix is available. Please avoid accessing data that is not your own, disrupting services, or publishing exploit details before remediation.

Scope

Security reports cover software and infrastructure maintained by the BLAQUE BAUX organization. Research disagreements, methodology questions, and ordinary defects belong in the affected repository's issue tracker.

Nothing in this policy creates a bug-bounty program or promise of compensation.

There aren't any published security advisories