Security reports are welcome for:
- Remote code execution, command injection, or unsafe subprocess usage
- Data exfiltration or path traversal in cache/download handling
- Server-side request forgery or unsafe proxying
- Credential leakage in configuration templates, docs, or logs
- Supply-chain risks in install or release automation
This project serves public data only. It should not be used to process PHI or other regulated patient data.
Please do not open a public GitHub issue for a suspected security problem.
Report privately to: security@ajhcs.org
Include:
- Affected file or server
- Reproduction steps
- Impact assessment
- Suggested remediation if you have one
We will acknowledge receipt and work on a fix before public disclosure.