For vulnerabilities in docassemble itself, follow the upstream process below — upstream is the authoritative codebase and fixes land there first.
For vulnerabilities in fork-only code (the divergent lines listed in
FORK.md and the .github/workflows/ harness), use GitHub's
private vulnerability reporting on this repository ("Report a
vulnerability" under the Security tab). Do not open a public issue.
To report a security issue, email jhpyle@gmail.com and include the phrase "docassemble security" in the subject line.
You will receive a response indicating the next steps in handling your report. After the initial reply to your report, you will be kept informed of the progress towards a fix and full announcement, and you may be asked for additional information or guidance.
Report security bugs in third-party modules to the person or team maintaining the module.
To learn more about ensuring security in docassemble, please see the Security section in the documentation.