Please do not open a public issue for a security problem.
Instead, either:
- Use GitHub's private vulnerability reporting (the Security tab → Report a vulnerability), or
- Or message a maintainer directly on GitHub, or in the community WhatsApp group. Please do not post the details in a public channel.
Please include:
- What the problem is and roughly how severe you think it is
- Steps to reproduce it
- Which version, branch, or commit you found it on
- A proof of concept if you have one
| When | What |
|---|---|
| Within 48 hours | We acknowledge your report |
| Within 7 days | We confirm whether it is a real issue and how severe |
| Within 30 days | We aim to have a fix released |
We will credit you in the advisory unless you would rather we did not.
This policy covers the code in this repository. It does not cover third-party services we link to, or someone's fork.
Found something while poking around? Report it, do not exploit it. Testing against your own local copy is fine and encouraged. Testing against live university systems is not, and is a disciplinary matter independent of this policy.
If you are not sure whether something counts, ask first. Nobody has ever been in trouble for asking.