Skip to content

Security: CSalcedoDataBI/.github

Security

SECURITY.md

Security policy

This policy applies to every public repository under CSalcedoDataBI, unless a repository publishes its own.

Reporting a vulnerability

Please do not open a public issue for a security problem. An issue is visible to everyone the moment it is filed, including for however long it takes to have a fix.

Two routes, in this order:

  1. GitHub private reporting — in the affected repository, go to the Security tab and choose Report a vulnerability. This is the preferred route: it stays attached to the repository, it is private, and it allows an advisory with credit to be published afterwards.
  2. Email to contacto@csalcedodatabi.com, if you have no GitHub account or private reporting is unavailable on that repository.

Include what makes it reproducible: the version, the steps, and what you expected to happen instead. An imperfect report beats no report — if you are not sure it counts as a security issue, send it anyway.

Write in Spanish if that is easier for you. It is the maintainer's first language, and a report that is easier to write is a report that actually gets sent.

What to expect

This is maintained by one person, not a company with an on-call rota, so the honest commitment is a modest one rather than an impressive one:

  • An acknowledgement within 5 working days.
  • An assessment, and either a fix or a decision not to fix, as soon as is practical.
  • Credit in the published advisory when your report leads to a fix, unless you would rather not have it.

If a week passes with no reply, try the other route. It is not disinterest — it means the message went missing.

Scope

What lives in these repositories: the code, the scripts, the templates and the published workflows. Most are analysis tools and visualisation templates that run on the machine of whoever installs them, so what matters most here is usually unintended code execution, a secret leaked into history, or a compromised dependency.

Findings in third-party dependencies belong upstream — but tell us anyway if a repository here is affected. Hearing it twice is better than not hearing it.

Disclosure

The preference is coordinated disclosure: fix, publish the advisory, give credit. When a problem affects people already using a tool, the priority is that they can update before the details are public.

There aren't any published security advisories