This is the default security policy for repositories in The Metadatastician
organisation. A repository with its own SECURITY.md overrides this one.
Please do not open a public issue for a security problem.
- Preferred — use the repository's Security tab → Report a vulnerability. This opens a private advisory visible only to maintainers.
- Fallback — email
sudo@metadatastician.art.
Please include what you can: affected repository and version, reproduction steps, and what an attacker could achieve. A partial report is worth more than no report.
- Acknowledgement within 72 hours. This estate is maintained by one person, so this is a good-faith target rather than a contractual SLA.
- An assessment of severity and affected repositories.
- Credit in the advisory if you would like it, or anonymity if you prefer.
In scope: vulnerabilities in code original to this organisation.
Out of scope: published advisories in third-party dependencies. Those are better raised as a normal issue so they can be tracked and updated — they are already public, so private disclosure gains nothing.
Several repositories here are games or experimental tools rather than production services. Please still report anything you find; we would rather hear it.