Skip to content

Security: adia/gcd-django

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities in public issues, pull requests or on the gcd-tech mailing list.

Report them privately instead, with Report a vulnerability in the Security & quality tab of this repository. Only you, the repository administrators and the people they add to the report can see it until it is published.

If the button is missing, private reporting is not enabled. Open an issue asking for a private security contact, without any details of the problem.

Please include:

  • the affected code (file, view or URL) and the branch or commit,
  • how to reproduce it on a development setup, e.g. a request or a test,
  • what an attacker gains, and whether it needs a login or special permissions.

Please reproduce issues on a local development setup (see docs/development/CORE_SETUP.md), not on the production or beta site. Until the report is published, do not push a fix or a proof of concept to your fork or open a pull request: forks of this repository are public.

There aren't any published security advisories