We take the security of this project seriously. If you discover a security vulnerability, please report it privately so we can address it before it is publicly disclosed.
Please do not report security vulnerabilities through public GitHub issues.
Instead, use one of the following private channels:
- Preferred: GitHub's private vulnerability reporting feature (the "Report a vulnerability" button under the repository's Security tab).
- Fallback: Email innovation@wdgpublichealth.ca with a description of the issue.
When reporting, please include as much of the following as you can:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof of concept.
- Any affected versions or configurations you are aware of.
- We will acknowledge your report as soon as we are able.
- We will investigate, keep you informed of our progress, and work on a fix.
- Once a fix is available, we will coordinate disclosure with you.
Please act in good faith and give us a reasonable opportunity to resolve an issue before any public disclosure. We appreciate your help in keeping this project and its users safe.