Skip to content

Security: OpenGene/viroflash

Security

SECURITY.md

Security and privacy reporting

Contact boman-ng boman.ngs@gmail.com privately with the affected version, a short description and a synthetic reproduction. Do not include real sample data or active credentials. Arrange a suitable private exchange before sharing sensitive evidence. No response-time SLA or enabled GitHub private reporting feature is assumed.

Outputs are not anonymized. Sample names, FASTA descriptions, reference fingerprints and results may identify their sources. HTML embeds every CSV row, not only Top 20. Review the entire HTML, CSV, perf.json and terminal diagnostics before sharing; errors may contain paths. Do not attach identifying reports to public issues.

CSV preserves original values. Import untrusted textual columns as text in a spreadsheet instead of allowing automatic formula interpretation.

Before making a private repository public, review its full history, releases and other copies for sensitive information; a clean working tree is not sufficient. Any discovered credential exposure requires its owner's revocation or rotation.

There aren't any published security advisories