Skip to content

Security: Montgomery-SLIC/slic

SECURITY.md

Security Policy

Supported Versions

Only the latest release receives security updates.

Version Supported
1.x.x yes

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Report vulnerabilities by email to Dr Chris Montgomery at c.montgomery@sheffield.ac.uk. Include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof of concept
  • The version of SLIC affected

Given that SLIC handles encrypted participant data, we take reports relating to the following areas most seriously:

  • Exposure of participant PII or response data
  • Authentication or authorisation bypass
  • Encryption key handling
  • Audio file enumeration for unpublished experiments

There aren't any published security advisories