Skip to content

Security: jvogan/codex-surface-atlas

SECURITY.md

Security reporting

This project is research software. Treat imported workspaces, molecular files, and generated reports as untrusted content. Use the current release or main branch when reproducing a suspected vulnerability; older versions do not have a separate security maintenance commitment.

Please try GitHub private vulnerability reporting to report a security issue privately. That form is available only if the repository owner has enabled private reporting and your account can access it. This document does not assert that the feature is enabled.

If the form is unavailable, open a minimal issue asking the maintainers to provide a private reporting channel. Do not include exploit details, secrets, private datasets, or sensitive logs in a public issue. Wait for a private channel before sharing the detailed report. There is no guaranteed response time or emergency support service.

A useful private report includes the affected version, impact, and a minimal synthetic reproduction. Remove credentials, personal information, and private research data. Please allow time to investigate and coordinate disclosure.

There aren't any published security advisories