This security policy applies to public projects under the Code for America organization on GitHub.
Security and bug fixes are generally provided only for the latest release of each project.
Security fixes are given priority and may be enough to cause a new version to be released.
We encourage responsible disclosure of security vulnerabilities. If you find something suspicious, we encourage and appreciate your report!
In order for vulnerability reports to reach the maintainers as soon as possible, the preferred way is to use the "Report a vulnerability" button under the "Security" tab of the associated GitHub project. This creates a private communication channel between the reporter and the maintainers.
If you are unable to use GitHub's vulnerability reporting workflow, or have strong reasons not to, please reach out to the Code for America security team at security@codeforamerica.org.
Please do not report security vulnerabilities through public GitHub issues.
To help us triage and resolve the issue quickly, please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce it
- The affected version(s), project, or URL
- Any relevant configuration, logs, or proof-of-concept
- A suggested fix, if you have one