This is the organization-wide security policy for NegruzziHub. It applies to every repository under this organization unless a specific project publishes its own.
If you've found a security issue in any NegruzziHub repository : a leaked credential, an authentication bypass, exposed data, or anything else that could put the club, the school, or a member at risk : please do not open a public issue describing it.
Instead, report it privately:
- Message current club leadership directly, or
- Use GitHub's private vulnerability reporting feature on the affected repository, if it's enabled
Please include:
- A description of the issue and where it is
- Steps to reproduce it, if you can
- What you think the potential impact is
Someone from club leadership will acknowledge your report and start looking into it. See CentralPoint's incident response guide for how we handle it internally. We'll keep you updated as it's resolved.
This applies to all repositories under the NegruzziHub organization. If in doubt about whether something counts, report it anyway.
Reporting responsibly, instead of exploiting or publicizing an issue, is genuinely appreciated. It's one of the most useful things a member can do for the club.