Skip to content

Security: ArchAstro/archastro-python

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Use GitHub private vulnerability reporting in the affected repository when it is available, or email security@archastro.ai.

Include the affected project and version or commit, reproduction steps, expected impact, and any proof-of-concept details that help us investigate.

We aim to acknowledge reports within five business days and will coordinate status updates and disclosure timing with the reporter. If you do not receive an acknowledgement, reply to the original message so the report stays in one thread.

When researching a vulnerability, do not access data that is not yours, degrade service, or retain credentials or personal information. Do not open a public issue or disclose the vulnerability publicly before a fix or a coordinated disclosure date.

Project-specific support windows and security details are documented in each repository when they differ from this organization-wide policy.

There aren't any published security advisories