Do not disclose suspected vulnerabilities in public issues, discussions, or pull requests. Report them privately to the SCORE organization administrators or to infoscore@us.es, including:
- Affected repository, version, or commit.
- Description and potential impact.
- Reproduction steps or proof of concept.
- Suggested mitigation, if available.
- Your preferred contact details.
Remove credentials, personal data, and other sensitive information from the report whenever possible.
The responsible maintainer will acknowledge the report when practical, validate the issue, coordinate remediation, and determine an appropriate disclosure timeline. Public disclosure must not occur before affected maintainers and relevant institutional stakeholders have had a reasonable opportunity to respond.
- Never commit secrets or credentials.
- Keep dependencies and actions reasonably up to date.
- Do not publish restricted research data.
- Document security limitations in research prototypes.
- Use private reporting for vulnerabilities that could affect users or infrastructure.