Security issues must be reported privately. Do not open a public issue containing exploit details, credentials, customer data, personal information, or sensitive operational information.
Use GitHub private vulnerability reporting for the affected repository whenever it is available:
- Open the repository's Security tab.
- Choose Report a vulnerability.
- Include the affected version/commit, impact, reproduction steps, and a suggested mitigation when available.
For organization-default policy concerns, report directly through T50-Systems/.github private vulnerability reporting.
If an affected repository does not expose private reporting, use the organization-default private reporting link above and name the affected repository. Do not create a public placeholder issue.
These are coordination targets, not a guarantee of remediation time:
- acknowledgement: within 3 business days;
- initial severity and scope triage: within 7 business days;
- critical/high status updates: at least weekly until resolution or mitigation;
- medium/low status updates: at least monthly while actively tracked;
- coordinated disclosure: after a fix or mitigation is available, unless immediate disclosure is required to protect users.
Repository-specific security policies may define stricter targets.
When safe to share privately, include:
- affected repository, package, version, commit, or deployment;
- concise vulnerability description and expected impact;
- reproduction steps or proof of concept;
- affected configurations and prerequisites;
- suggested mitigation or patch;
- preferred credit name, or a request to remain anonymous.
Unless a repository states otherwise, fixes target the default branch and latest released version. Older versions may receive fixes at maintainer discretion based on severity, exploitability, and upgrade feasibility.
Give maintainers a reasonable opportunity to investigate and release a fix before public disclosure. Reports are shared only with people needed to triage and remediate the issue. Retaliation against good-faith security researchers is not tolerated.