This policy applies to submissions of potential security vulnerabilities related to Agos or its operated digital infrastructure.
We take the security of Agos seriously. If you believe you’ve found a security issue affecting this repository, please do not open a public GitHub issue. Doing so may put the project and its users at risk before a patch can be applied.
Instead, please submit your findings privately using the designated contact channel below.
Please report all security vulnerabilities via email to: neil.c.artus@gmail.com
To help us quickly triage, validate, and resolve the issue, please include the following details in your email:
- Vulnerability Type: Briefly categorize the issue (e.g., Cross-Site Scripting (XSS), Remote Code Execution (RCE), Broken Access Control).
- Description: A clear, concise explanation of the vulnerability and its potential impact on the system or users.
- Steps to Reproduce: A detailed, step-by-step guide on how to replicate the issue.
- Proof of Concept (PoC): Any relevant code snippets, screenshots, or screen recordings that demonstrate the exploit in action.
- Environment: The specific version of Agos and details about the environment (e.g., OS, browser) where the bug was discovered.
- Suggested Mitigation (Optional): If you have thoughts on how the vulnerability can be patched, we welcome your suggestions.
When you submit a report, here is how we will handle it:
- Acknowledgement: We aim to acknowledge receipt of your vulnerability report within 48 hours.
- Triage & Investigation: We will investigate the issue to confirm its validity and determine its severity. We may reply to your email requesting further clarification or details.
- Updates: We commit to keeping you reasonably informed of our progress as we develop and test a patch.
- Coordinated Disclosure: We kindly ask that you maintain strict confidentiality and avoid disclosing the vulnerability publicly until we have successfully released a fix.
- Recognition: Once the issue is resolved, we will gladly acknowledge your contribution to the security of Agos (unless you prefer to remain anonymous).