Skip to content

Security: XiaoShuinan/infrared-physics-lab

Security

SECURITY.md

Security policy

Supported versions

Until the first stable release, security fixes target the latest commit on main and the latest 0.1.x release, if one exists. Older snapshots may not receive fixes.

Report a vulnerability privately

Use GitHub’s Report a vulnerability / private security-advisory feature for:

https://github.com/XiaoShuinan/infrared-physics-lab/security/advisories/new

Do not open a public issue for an unpatched vulnerability. Include:

  • affected version or commit;
  • environment and required toolbox versions;
  • minimal reproduction steps or proof of concept;
  • plausible impact and attack prerequisites;
  • suggested mitigation, if known;
  • whether you need coordinated disclosure credit.

Remove API keys, SSH keys, personal data, proprietary data, and unrelated files from the report. If the private advisory channel is not yet available, contact the repository owner through a previously published private channel and mention only that you have a security report; do not send exploit details publicly.

Response process

The maintainers aim to acknowledge a complete report within seven business days. Investigation and remediation time depend on reproducibility and severity. The project will coordinate a fix, release note, and disclosure date when possible. This is a best-effort open-source policy, not a service-level agreement.

Please allow reasonable remediation time before public disclosure. Good-faith research that avoids privacy violations, service disruption, data destruction, and unnecessary access is welcome.

Scientific correctness is different

Incorrect physics, units, assumptions, or reference values usually belong in a Physics Validation issue, not a private security report. Use the security channel only when public disclosure would create a credible security risk.

Scope notes

MATLAB and third-party actions/services are governed by their vendors’ security processes. Vulnerabilities in those products should also be reported upstream. A malformed input that produces a clear validation error is not by itself a vulnerability; unsafe code execution, path traversal, credential exposure, or unbounded resource consumption may be.

There aren't any published security advisories