Skip to content

Security: ScientFactory/scient-desktop

SECURITY.md

Security policy

Reporting a vulnerability

Report suspected vulnerabilities privately through GitHub private vulnerability reporting. Do not include vulnerability details in a public issue or discussion.

Include the affected revision, operating system, reproduction steps, observed impact, and any relevant logs with secrets removed. A maintainer will acknowledge the report, investigate it, and coordinate disclosure or remediation as appropriate.

Scope

This policy covers Scient-owned code in this repository. Vulnerabilities that only affect an external provider, connected agent, or inherited upstream project should be reported to that project's security channel. If the ownership boundary is unclear, report privately here and a maintainer will route it safely.

There aren't any published security advisories