We take the security of our project seriously. If you discover a security vulnerability, please report it to us privately to protect the project and its users.
Caution
Please do not report security vulnerabilities through public GitHub issues or discussion forums.
Instead, please contact one of our professors directly and privately:
- Prof. Foley
- Prof. Sauppé
- Any of the currently active project maintainer
When reporting a vulnerability, please include as much detail as possible:
- Description: A clear description of the vulnerability and its potential impact.
- Reproduction Steps: Detailed steps to reproduce the vulnerability.
- Proof of Concept: Code snippets, screenshots, logs, or other evidence demonstrating the vulnerability.
- Affected Components/Versions: Specify which parts or versions of the project are affected.
- Suggested Mitigation (Optional): If you have ideas on how to fix the vulnerability.
We appreciate your efforts in responsibly disclosing your findings and helping us keep this project secure. We will acknowledge receipt of your report and work towards addressing the vulnerability promptly.