If you discover a potential security issue in Prism, please report it responsibly and privately.
Please do not open a public GitHub issue. Use GitHub Security Advisories (GHSA) so the report is handled privately and gets a proper advisory workflow:
- Go to the repository’s Security tab: https://github.com/siiway/prism/security/advisories
- Click Report a vulnerability (or New advisory).
- Provide:
- Affected version(s) / commit
- Reproduction steps
- Impact and severity assessment
- Possible exploit scenario and any proof-of-concept (redacted if needed)
- Suggested fix, if available
- Reports submitted via GHSA are visible only to maintainers and the reporter during triage.
- Confirmed vulnerabilities can be coordinated and published as a GitHub advisory with a
GHSA-xxxx-xxxx-xxxxidentifier. - This helps avoid premature disclosure and supports coordinated disclosure.
Please give us reasonable time to investigate and fix the issue before public discussion. We ask that you keep details private until we confirm a fix and publish advisory/patched release notes.
We aim to acknowledge reports promptly and provide status updates as they become available.