To report a security vulnerability, either:
-
GitHub Private Vulnerability Reporting (preferred): Navigate to the Security tab on the affected repository, click "Advisories", then "Report a vulnerability". See the GitHub guide for details.
-
Email: Send a report to
complytime-security@redhat.comwith a description of the issue and the affected project(s).
Do NOT open a public GitHub issue for security vulnerabilities.
For the full organization-wide security policy, including what to include in a report, public disclosure process, and supported versions, see the ComplyTime Security Policy.