Skip to content

Security: Cyber-Info/.github

Security

SECURITY.md

Security Policy

Cyber Info values the work of security researchers who help us protect our community, projects, and services. We encourage responsible, good-faith vulnerability research and coordinated disclosure.

This file is the default security policy for Cyber Info repositories that do not provide their own SECURITY.md. If a repository has a separate security policy, that repository-specific policy takes precedence.

Reporting a Vulnerability

Please do not open a public GitHub issue, discussion, or pull request for a suspected vulnerability.

Report vulnerabilities through one of these channels:

Use our PGP key when a report or its attachments contain sensitive information.

A useful report should include, when available:

  • The affected repository, service, URL, component, and version or commit
  • A clear description of the vulnerability and its potential impact
  • Reproduction steps or a minimal proof of concept
  • Relevant logs, screenshots, requests, responses, or other supporting evidence
  • Any conditions required to reproduce the issue
  • Suggested remediation, if known
  • Your preferred contact information and any disclosure plans

Please submit one vulnerability per report unless multiple findings must be combined to demonstrate their impact.

Research Guidelines

When conducting security research:

  • Test only systems and data that you are authorized to access.
  • Make a good-faith effort to avoid privacy violations, data loss, service disruption, and harm to users.
  • Access, modify, retain, or share only the minimum data necessary to demonstrate the issue.
  • Do not use social engineering, phishing, physical attacks, denial-of-service techniques, or destructive testing.
  • Do not establish persistence or pivot to unrelated systems.
  • Stop testing and report the issue promptly if you encounter sensitive or personal data.
  • Keep vulnerability details confidential while we investigate and coordinate remediation and disclosure.

Our complete scope, rules, exclusions, safe-harbor terms, and disclosure process are maintained in the Cyber Info Vulnerability Disclosure Program. That policy governs if it conflicts with this summary.

What to Expect

We will review reports submitted through the designated channels and work with researchers to understand and address valid findings. Response and remediation times depend on the severity and complexity of the issue.

Please allow us a reasonable opportunity to investigate and remediate a vulnerability before publishing details. Coordinate any public disclosure with our security team.

Eligible researchers may be recognized in our Hall of Fame, subject to our disclosure policy and the researcher's consent. Submission of a report does not create an entitlement to payment or another reward.

Security Contact Information

Our canonical machine-readable security contact information is available at:

There aren't any published security advisories