Skip to content

Security: Brunaugh-Lab/diffractomorph

Security

SECURITY.md

Security policy

Supported versions

Before the first tagged release, security fixes are made on the default branch. After releases begin, fixes are provided for the latest public release.

Reporting

Do not open a public issue for a suspected credential, private-data exposure, or other disclosure vulnerability. Use GitHub's private vulnerability-reporting feature for this repository. If that feature is unavailable, contact the repository owner privately through the organization profile.

Include the affected version, file or command, impact, and a minimal reproduction. Do not attach confidential research data.

Scope

DiffractoMorph processes user-supplied scientific files. Reports involving path traversal, unsafe archive handling, credential disclosure, unintended network access, or leakage of input data are in scope. Scientific disagreements without a security or privacy impact belong in the regular issue tracker.

There aren't any published security advisories