Skip to content

Security: stacknil/scientific-computing-toolkit

SECURITY.md

Security Policy

Reporting a vulnerability

Do not disclose suspected vulnerabilities publicly in issues, pull requests, or discussions.

If the target repository provides a documented private reporting path, use that path. If the account profile or target repository documents a private contact route, use that route before opening a public issue. If no documented private route is available, open a minimal public issue without exploit details and request a secure contact route.

Include the following where possible

  • Affected repository
  • Affected version, tag, or commit
  • Vulnerability summary
  • Impact assessment
  • Reproduction conditions
  • Proof of concept, if safe and necessary
  • Suggested remediation, if available

Disclosure expectations

Please allow reasonable time for triage and remediation before public disclosure.

Scope note

This default policy is a shared fallback for repositories that do not define a repository-specific security policy. Repositories with their own SECURITY.md or private reporting instructions should be treated as authoritative over this default.

There aren't any published security advisories