This policy applies to every Workoho repository that does not carry its own
SECURITY.md.
Do not open a public issue for a vulnerability.
- Where the repository's Security tab offers Report a vulnerability, use that. The report stays private between you and the maintainers.
- Where it does not, write to yourfriends@workoho.com and name the repository. Send no exploit code or personal data beyond what is needed to reproduce the problem.
A useful report names the affected repository and version or commit, what happens, the steps to reproduce it, and what an attacker gains.
Reports are read by the people who maintain the repository. We tell you whether we treat the report as a vulnerability, and we credit you in the fix if you want that.