Skip to content

Security: broadinstitute/SpliceAI-lookup

SECURITY.md

Security Policy

SpliceAI-lookup is an open-source (MIT-licensed) tool that also runs as a hosted web instance at https://spliceailookup.broadinstitute.org with a public REST API. This policy covers both the source code in this repository and the hosted instance.

Reporting a Vulnerability

Please report security vulnerabilities through GitHub's private vulnerability reporting: Report a vulnerability (the repository's Security tab → Report a vulnerability).

This will open an advisory visible only to the maintainers.

Do not open a public GitHub issue for a security problem.

Please include:

  • a description of the vulnerability and its impact
  • steps to reproduce it
  • the affected component (hosted instance, REST API, or a path in this repository)
  • any suggested fix or mitigation.

What to expect:

  • Credit in the resulting security advisory once a fix is released, unless you prefer to remain anonymous.

For non-security bugs and feature requests, please use the public issue tracker.

There aren't any published security advisories