Please report security issues privately to librecourseuy@gmail.com. Do not open a public issue for a vulnerability.
Include as much as you can:
- the affected repository, and the version or commit;
- a description of the issue and its impact;
- steps to reproduce, or a proof of concept;
- any suggested fix or mitigation; and
- whether you want public credit.
This policy covers the LibreCourseUY repositories and any service we operate. It does not cover third-party projects, forks, or self-hosted instances run by other people.
We aim to acknowledge reports within a few days. We will investigate, keep you posted on the fix, and credit you in the release notes if you want. Please give us reasonable time to fix the issue before any public disclosure.
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and only test against their own accounts or instances.
This document works alongside:
CODE_OF_CONDUCT.mdCONTRIBUTING.mdGOVERNANCE.md