This policy covers every public repository under github.com/Aitherium — the aw*
bricks, AitherZero, AitherConnect and the rest of the family.
Please do not report a vulnerability through a public issue. An issue is public the moment it is opened, and it cannot be taken back.
- Preferred — GitHub private vulnerability reporting. Open the repository's
Security tab and choose Report a vulnerability
(
https://github.com/Aitherium/<repository>/security/advisories/new). The report is visible only to the maintainers, and the fix and your credit are published from the same advisory. - Email: security@aitherium.com — for a report that spans several repositories, or when you cannot use GitHub.
Please include: the type of issue, the affected repository and file paths, the commit / tag / branch (or a direct URL) of the affected code, steps to reproduce, a proof-of-concept if you have one, and the impact as you understand it. A plain-text report is fine.
- Acknowledgement within 3 business days of receipt.
- An assessment, and a planned fix window, in the acknowledgement or the next reply.
- Credit in the published advisory, unless you prefer to stay anonymous.
Every public repository under github.com/Aitherium. Third-party dependencies belong with their own maintainers; social engineering of Aitherium staff is out of scope.
This file is generated by AitherOS/dev/tools/gen_org_profile.py and published
by push_org_profile.py. Editing it by hand will be overwritten — change the
generator instead.