Do not report vulnerabilities, active incidents, credentials, private URLs, deployment details, private legal documents, personal data or other sensitive information in public issues or Discussions.
The canonical project-wide policy is published at openlegalcore.org/security.
- If the matter affects a specific public repository, use that repository's Security tab and GitHub Private Vulnerability Reporting when available.
- Otherwise, or when the affected boundary is unclear, email security@openlegalcore.org with the subject OpenLegalCore security report.
- Begin with a concise description. Share only the minimum information needed to establish a safe private reporting route, and do not attach confidential material until the recipient and handling method are confirmed.
If neither route is temporarily available, do not open a public report.
- the affected component and version or commit;
- observed behavior, likely impact and required preconditions;
- reproducible steps using synthetic data where possible;
- relevant evidence with secrets and personal data removed;
- any known mitigation; and
- a safe contact path for clarification.
Do not send credentials, tokens, private keys, personal or legal documents, production datasets, third-party confidential data or unredacted operational logs. Describe the category of sensitive material first and wait for a suitable exchange method.
A report is reviewed privately, clarification is requested when needed and disclosure is coordinated after a safe fix or mitigation is available. The project does not promise a response time and does not operate a bug-bounty program.
This reporting guidance does not authorize testing. Do not disrupt services, use social engineering, access third-party data, establish persistence or exfiltrate information.