Until the first stable release, security fixes target the latest commit on main and the latest 0.1.x release, if one exists. Older snapshots may not receive fixes.
Use GitHub’s Report a vulnerability / private security-advisory feature for:
https://github.com/XiaoShuinan/infrared-physics-lab/security/advisories/new
Do not open a public issue for an unpatched vulnerability. Include:
- affected version or commit;
- environment and required toolbox versions;
- minimal reproduction steps or proof of concept;
- plausible impact and attack prerequisites;
- suggested mitigation, if known;
- whether you need coordinated disclosure credit.
Remove API keys, SSH keys, personal data, proprietary data, and unrelated files from the report. If the private advisory channel is not yet available, contact the repository owner through a previously published private channel and mention only that you have a security report; do not send exploit details publicly.
The maintainers aim to acknowledge a complete report within seven business days. Investigation and remediation time depend on reproducibility and severity. The project will coordinate a fix, release note, and disclosure date when possible. This is a best-effort open-source policy, not a service-level agreement.
Please allow reasonable remediation time before public disclosure. Good-faith research that avoids privacy violations, service disruption, data destruction, and unnecessary access is welcome.
Incorrect physics, units, assumptions, or reference values usually belong in a Physics Validation issue, not a private security report. Use the security channel only when public disclosure would create a credible security risk.
MATLAB and third-party actions/services are governed by their vendors’ security processes. Vulnerabilities in those products should also be reported upstream. A malformed input that produces a clear validation error is not by itself a vulnerability; unsafe code execution, path traversal, credential exposure, or unbounded resource consumption may be.