Skip to content

Security: pyragogy/working-patterns

Security

SECURITY.md

Security and responsible disclosure

Working Patterns is currently a research-data repository and does not operate a public service, agent, or MCP endpoint.

Report privately when appropriate

If a future code contribution introduces a vulnerability that could expose credentials, private research material, contributor data, or downstream systems, do not publish exploit details in a normal issue before maintainers can assess them.

For ordinary research/data integrity problems — incorrect citations, broken provenance, licence errors, unsupported claims — use a public issue or pull request because inspectability is part of the project method.

Data minimisation

Do not commit:

  • credentials or API keys;
  • confidential organisational records;
  • personal data that is unnecessary for the research claim;
  • private incident material without appropriate permission;
  • copyrighted source archives merely for convenience.

Open research does not require maximal exposure.

There aren't any published security advisories