Skip to content

Security: legalize-dev/legalize

Security

SECURITY.md

Security policy

Reporting a vulnerability

If you believe you have found a security vulnerability in the Legalize hub, please report it responsibly.

Do not open a public GitHub issue.

Instead, email security@legalize.dev with:

  • A description of the issue
  • Steps to reproduce
  • The affected component and version
  • Any proof-of-concept code, if applicable

We aim to acknowledge reports within 3 business days and ship a fix within 30 days for confirmed vulnerabilities.

Scope

In scope:

  • The public hub repository and its documentation
  • The corpus specification and schema definitions
  • Index and metadata structures

Out of scope:

  • Issues in third-party dependencies that have a pending upstream fix
  • The Legalize API — report those at the web repo or the same email
  • The pipeline engine — report those at the engine repo or the same email

Signed commits

Maintainer commits are GPG-signed. Community PRs are not required to sign, but the merge commit will be signed.

There aren't any published security advisories