If you believe you have found a security vulnerability in the Legalize hub, please report it responsibly.
Do not open a public GitHub issue.
Instead, email security@legalize.dev with:
- A description of the issue
- Steps to reproduce
- The affected component and version
- Any proof-of-concept code, if applicable
We aim to acknowledge reports within 3 business days and ship a fix within 30 days for confirmed vulnerabilities.
In scope:
- The public hub repository and its documentation
- The corpus specification and schema definitions
- Index and metadata structures
Out of scope:
- Issues in third-party dependencies that have a pending upstream fix
- The Legalize API — report those at the web repo or the same email
- The pipeline engine — report those at the engine repo or the same email
Maintainer commits are GPG-signed. Community PRs are not required to sign, but the merge commit will be signed.