Skip to content

Security: aces-aswf/.github

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you thank you have discovered a potential vulnerability, please report it using GitHub’s built-in Security Advisories feature. This ensures the report remains private until it is reviewed by maintainers and an appropriate fix is in place.

  1. Go to this repository’s "Security" tab.
  2. Select "Report a vulnerability".
  3. Provide as much detail as possible so we can investigate and address the issue promptly.

Please do not disclose any details of the issue publicly until we have had a chance to investigate and provide a fix. This helps keep the project and its users safe.

Please only submit reports via this method if you are absolutely sure you have found a true security vulnerability.

What constitutes a True Vulnerability?

A true vulnerability is a flaw that an attacker can use to harm the system, such as:

  • Remote Code Execution (RCE)
  • Unauthorized access to private data
  • Exposed credentials (API keys, passwords, etc.)

The following issues are NOT considered true vulnerabilities and will be closed:

  • Standard bugs, crashes, or software errors
  • Missing features or feature requests
  • Issues caused by how you set up or configured the software

Non-security bugs should be filed using the regular issue tracker.

There aren't any published security advisories