Responsible disclosure guidelines for the UniPD Computer Engineering archive.
This policy covers security issues involving the repository's scripts, dependencies, build tools, CI workflows, automation, and configuration.
It does not cover factual, mathematical, technical, or typographical errors in the study materials. See Content errors below.
Security fixes are applied only to the current default branch.
Do not open a public issue containing vulnerability details.
Submit security reports privately through GitHub Private Vulnerability Reporting.
Include, when possible:
- a concise description of the issue;
- the affected component or file;
- its potential impact;
- reproducible steps or a proof of concept;
- any suggested mitigation.
Do not include real credentials, access tokens, personal information, or other unnecessary sensitive data.
If private vulnerability reporting is unavailable, open a public issue requesting a private reporting channel without disclosing technical details.
Reports are normally acknowledged within three days, although response times may vary.
The maintainer may request additional information while investigating the issue. Relevant updates will be provided when available.
Please do not disclose the vulnerability publicly until a fix has been released or disclosure has been coordinated with the maintainer. Reporters may be credited in a security advisory or release notes when appropriate, unless they request anonymity.
The notes in this repository are unofficial, student-created material and may contain errors, omissions, outdated information, or inaccurate AI-assisted content.
Content problems are not security vulnerabilities. Mistakes in notes, broken links, documentation problems, and PDF compilation or rendering issues should be reported through a public issue or addressed with a pull request unless they create an actual security risk. Include a reliable source when appropriate.
For additional guidance, see the academic disclaimer in README.md and the contribution requirements in CONTRIBUTING.md.
