English | Italiano
Fablab Imperia is a volunteer-run non-profit. We take security seriously and appreciate the effort it takes to report a problem responsibly. This policy applies to all Fablab Imperia repositories.
Please do not report security vulnerabilities through public issues, pull requests, or discussions. Public disclosure before a fix is available can put users at risk.
Instead, report privately in one of two ways:
- GitHub private reporting — on the affected repository, go to the Security tab and choose Report a vulnerability (if private vulnerability reporting is enabled). This keeps the report confidential and tied to the code.
- Email — write to info@fablabimperia.org with the details below.
A good report helps us understand and fix the issue faster. Where you can, please include:
- The repository and version, tag, or commit affected
- A description of the vulnerability and its potential impact
- Steps to reproduce it, or a proof of concept
- Any suggested fix or mitigation, if you have one
We are a small volunteer team, so we can't promise a formal response time, but we will do our best to:
- Acknowledge your report as soon as we reasonably can
- Investigate and keep you informed of progress
- Fix confirmed issues and, where appropriate, credit you for the discovery (only if you wish)
We ask that you give us a reasonable amount of time to address the issue before any public disclosure, and that you avoid accessing or modifying other people's data, or disrupting our services, while investigating.
This policy covers the code and content in Fablab Imperia's repositories. We do not run a paid bug-bounty program. Please act in good faith; good-faith research and reporting will always be met with thanks, not legal action.
Thank you for helping keep Fablab Imperia and its community safe.