Skip to content

Security: LibreCourseUY/.github

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security issues privately to librecourseuy@gmail.com. Do not open a public issue for a vulnerability.

Include as much as you can:

  • the affected repository, and the version or commit;
  • a description of the issue and its impact;
  • steps to reproduce, or a proof of concept;
  • any suggested fix or mitigation; and
  • whether you want public credit.

Scope

This policy covers the LibreCourseUY repositories and any service we operate. It does not cover third-party projects, forks, or self-hosted instances run by other people.

What to expect

We aim to acknowledge reports within a few days. We will investigate, keep you posted on the fix, and credit you in the release notes if you want. Please give us reasonable time to fix the issue before any public disclosure.

Safe harbor

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and only test against their own accounts or instances.

Relationship to other documents

This document works alongside:

  • CODE_OF_CONDUCT.md
  • CONTRIBUTING.md
  • GOVERNANCE.md

There aren't any published security advisories