Skip to content

Security: carson-evans/CommonMASS

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security issue, please do not create a public GitHub issue.

Instead, report it privately to the maintainers by contacting the project team directly through university email or the team communication channel used for this project.

Please include:

  • a clear description of the issue
  • steps to reproduce it
  • affected files or features
  • any suggested fix, if you have one

We will review the report and respond as quickly as possible.

Scope

Examples of sensitive issues include:

  • exposed secrets or credentials
  • insecure API behavior
  • access control problems
  • unsafe file handling
  • vulnerabilities affecting deployed cloud resources

There aren’t any published security advisories