Skip to content

Security: xlc-dev/apphub

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue. Use Report a vulnerability in the repository's Security tab so the report and any fix can be discussed privately.

Include the affected part, impact, reproduction steps, and any fix you suggest. Relevant reports include validation bypasses, unsafe downloads, exposed workflow credentials, incorrect integrity checks, unsafe generated content, and website vulnerabilities.

A vulnerability in an upstream application is normally best reported to that application. Report it to AppHub when AppHub misrepresents the application, bypasses its own validation, or exposes users or infrastructure to additional risk.

There aren't any published security advisories