The following versions of this project are currently supported with security updates:
| Version | Supported |
|---|---|
| main | ✅ |
| older branches / forks | ❌ |
If you discover a security vulnerability, please report it privately and do not open a public GitHub issue.
Please send reports to:
- Primary contact: Dont know who to add here yet, maybe osburn?
- Email: dont know who to add here yet, maybe osburn?
- Backup contact: dont know who to add here yet, maybe osburn?
- Maintainer:: dchoang@asu.edu
If possible, include the following information in your report:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The part of the system affected
- Any proof-of-concept, screenshots, or logs
- The potential security impact
- Suggested remediation, if known
After submitting a report, you can expect:
- An acknowledgment within 3-5 business days
- An initial assessment of the report
- Follow-up questions if additional detail is needed
- Updates on remediation status when appropriate
We will make a good-faith effort to:
- Confirm the vulnerability
- Assess its severity and impact
- Remediate the issue in a reasonable timeframe
- Credit the reporter, if appropriate and desired
To help protect users and the project, please:
- Do not publicly disclose the issue until it has been reviewed and addressed
- Do not exploit the vulnerability beyond what is necessary to demonstrate its existence
- Do not access, modify, or delete data that does not belong to you
- Do not perform denial-of-service, spam, or destructive testing
We appreciate responsible disclosure and will work with reporters in good faith.
This policy applies to:
- The main application code in this repository
- Related authentication, authorization, and session-handling logic
- Report generation and supporting APIs
- Deployment and configuration issues directly related to this repository
This policy does not apply to:
- Third-party services or providers outside this repository
- Issues in unsupported forks or outdated branches
- General feature requests or non-security bugs
A helpful report often includes:
- Affected file, endpoint, or feature
- Attack scenario
- Preconditions required for exploitation
- Impact on confidentiality, integrity, or availability
- Any temporary mitigation recommendations
We will not take action against security researchers who:
- Make a good-faith effort to avoid privacy violations, service disruption, and data destruction
- Report vulnerabilities promptly and privately
- Act within the bounds of this policy
Security fixes may be released without advance notice. In some cases, details may be withheld until affected systems have been patched.
Thank you for helping keep this project and its users safe.