Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
If you believe you have found a security vulnerability in the AA-SI Workbench, report it privately so it can be addressed before public disclosure:
- Use GitHub's private vulnerability reporting ("Report a vulnerability" under the Security tab), if enabled for this repository, or
- Email the maintainers privately.
Please include, to the extent you can:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof of concept.
- Affected component(s) and version(s) or commit.
- Any suggested mitigation.
- We will acknowledge your report and begin investigating.
- We will keep you informed of remediation progress.
- We will credit reporters who wish to be acknowledged once a fix is released.
During early development, only the latest main branch is supported with
security updates. A formal support matrix will be published with the first
tagged release.
Do not include sensitive, embargoed, or personally identifiable information in a
vulnerability report. See data/README.md for the project's
data-handling expectations.