SpliceAI-lookup is an open-source (MIT-licensed) tool that also runs as a hosted web instance at https://spliceailookup.broadinstitute.org with a public REST API. This policy covers both the source code in this repository and the hosted instance.
Please report security vulnerabilities through GitHub's private vulnerability reporting: Report a vulnerability (the repository's Security tab → Report a vulnerability).
This will open an advisory visible only to the maintainers.
Do not open a public GitHub issue for a security problem.
Please include:
- a description of the vulnerability and its impact
- steps to reproduce it
- the affected component (hosted instance, REST API, or a path in this repository)
- any suggested fix or mitigation.
What to expect:
- Credit in the resulting security advisory once a fix is released, unless you prefer to remain anonymous.
For non-security bugs and feature requests, please use the public issue tracker.