Skip to content

Security: Internet2/i2ccc

Security

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly by emailing:

tmanik@internet2.edu

Please do not open a public GitHub issue for security vulnerabilities.

What to include in your report

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue (proof-of-concept or exploit code if applicable)
  • Any relevant logs, screenshots, or other supporting information
  • The version or commit hash where the issue was found

Coordinated Disclosure Policy

We follow a coordinated (responsible) disclosure process:

  1. Report — Send your findings to tmanik@internet2.edu.
  2. Acknowledgement — We will acknowledge receipt of your report within 5 business days.
  3. Investigation — We will investigate the issue and keep you informed of our progress.
  4. Fix — We will work to remediate confirmed vulnerabilities in a timely manner.
  5. Disclosure — We will coordinate with you on an appropriate timeline for public disclosure after a fix is available.

We ask that you give us a reasonable amount of time to address the issue before any public disclosure.

Supported Versions

We only provide security fixes for the latest version of this project.

Contact

For non-security-related issues, please open a GitHub issue.

There aren’t any published security advisories