Security matters to us.
If you discover a vulnerability in a Hack SP project, please do not create a public GitHub issue containing details that could make the vulnerability easier to exploit.
Send the report privately to:
Please include, when possible:
- the affected repository or service;
- a description of the vulnerability;
- steps to reproduce it;
- the possible impact;
- and any suggested fix you may have.
You don't need to have a complete solution before reporting something.
We'll review the report, investigate the issue and coordinate a fix when necessary.
Please give us a reasonable opportunity to address the vulnerability before publishing technical details publicly.
Thanks for helping keep Hack SP and its community safe.