Skip to content

Security: datacatalysis/prodes

Security

SECURITY.md

Security

Reporting a vulnerability

Report it privately rather than as a public issue: use Security > Report a vulnerability on this repository, or the contact page at datacatalysis.com if that is not open to you. Say what you found and how to reproduce it.

This is maintained by a small team, so there is no formal response time. You will get an acknowledgement and a plain answer about what we intend to do.

A wrong number is a bug rather than a vulnerability, so open an issue for it. A credential committed to this repository is a vulnerability: report it privately, and assume it is live until it has been rotated.

Supported versions

The latest release on main. Fixes go into the next release rather than being backported, and the version that produced any output is recorded in prodes_run.json inside the bundle.

There aren't any published security advisories