Skip to content

Security: chidou59/ref-reconstructor

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not publish credentials, private documents, unpublished datasets, or an exploitable proof of concept in a public Issue.

For a suspected vulnerability, use GitHub's private vulnerability reporting feature on the affected repository when it is available. Include the affected version, impact, reproduction conditions, and a minimal sanitized example.

Supported versions

These are small, actively evolving projects. Security fixes target the latest main branch unless a repository explicitly documents a supported release series.

Scope

Security reports may include unsafe file handling, path traversal, credential exposure, dependency risks, untrusted document processing, and unintended disclosure of local data. Incorrect scientific predictions or upstream metadata errors are normally correctness issues rather than security vulnerabilities.

There aren't any published security advisories