Security contact
Security here means two things: the integrity of the evidentiary record, and the protection of victim and third-party personal information. The second one is the urgent one.
Report these privately. Never in a public issue
A redaction miss — personal information of a victim, a minor, or an uninvolved third party
A person named or identifiable who should be on the exclusion list
Content published beyond the scope of documented consent
An evidence-integrity problem, such as a file whose hash no longer matches its manifest entry
A leaked credential, token, or investigator personal information
Open a private security advisory on the public repository. It stays private, stays attached to the repository, and does not become public unless a maintainer publishes it.
Email if you do not have a GitHub account, or if the advisory form will not accept what you need to say.
Do not put the sensitive material in the report
| Include (non-sensitive metadata only) | Never include |
|---|---|
| The affected file path, release tag, or commit SHA, and a section reference | Names, images, or contact details of a victim, a minor, or a third party |
| The category of problem, and why it is sensitive, in general terms | Quoted excerpts, screenshots, or attachments of the exposed content |
| Any suggested remediation | Credential or token values. Report that one is exposed and where — never paste the value |
Expect acknowledgment within 3 business days. Confirmed exposure of victim or minor personal information is the highest priority and is remediated before any other work continues. Everything else — a broken link, a typo, a factual correction — belongs in a normal public issue.