Report suspected vulnerabilities privately so we can protect affected People, coordinate a fix and preserve the evidence needed for review.
Do not open a public issue. Email security@heyrafiki.space with:
- the repository and version affected
- what an attacker could do with it
- the steps to reproduce
- a proof of concept, if you have one
We acknowledge receipt, establish a private coordination channel and provide a triage status as the investigation progresses. Reports with a credible risk to confidentiality, integrity, authentication or Care continuity are prioritized.
Give us a reasonable opportunity to investigate and ship a fix before public disclosure. We share material status changes and coordinate the disclosure date with the reporter. We credit reporters by name when they want attribution.
Send the minimum needed to explain the problem. Never include real personal or health data in a report or a proof of concept. If a vulnerability exposes real records, tell us what you found and stop there. Do not download, keep or share them.
Automated scanner output with no demonstrated impact, missing headers with no exploit path, and findings that require an already-compromised device or account.
Good-faith research stays within accounts, projects and data you own or have written authorization to test. Do not use social engineering, denial of service, credential attacks, persistence, destructive actions or tests that could interrupt Care. Stop and report immediately if you encounter personal or health data.