Skip to content

Security: hyperpolymath/PolyglotFormalisms.jl

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in PolyglotFormalisms.jl, please report it by:

  1. Email: j.d.a.jewell@open.ac.uk
  2. GitHub Security Advisory: Use the "Security" tab to report privately

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

We aim to respond to security reports within 48 hours.

Security Practices

  • All GitHub Actions are SHA-pinned to prevent supply chain attacks
  • Dependencies are minimal (Test stdlib only)
  • OpenSSF Scorecard runs weekly
  • CodeQL analysis enabled

There aren't any published security advisories