Skip to content

Security: nmfs-ost/AA-SI_Workbench

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

If you believe you have found a security vulnerability in the AA-SI Workbench, report it privately so it can be addressed before public disclosure:

  • Use GitHub's private vulnerability reporting ("Report a vulnerability" under the Security tab), if enabled for this repository, or
  • Email the maintainers privately.

Please include, to the extent you can:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, or a proof of concept.
  • Affected component(s) and version(s) or commit.
  • Any suggested mitigation.

What to expect

  • We will acknowledge your report and begin investigating.
  • We will keep you informed of remediation progress.
  • We will credit reporters who wish to be acknowledged once a fix is released.

Supported versions

During early development, only the latest main branch is supported with security updates. A formal support matrix will be published with the first tagged release.

Handling of data

Do not include sensitive, embargoed, or personally identifiable information in a vulnerability report. See data/README.md for the project's data-handling expectations.

There aren't any published security advisories