This policy provides a private route for reporting credentials, personal or confidential information, unsafe publication, malicious repository behavior, or another security-sensitive condition affecting AI Dev Days.
It complements the Code of Conduct, contribution SOP, and publication-safety guidance.
The latest approved release and the default branch receive security-sensitive corrections. Historical event packets may be corrected when the consequence warrants it even if their tool guidance is otherwise preserved as point-in-time material.
Do not place credentials, personal information, private evidence, attendee or client data, exploit instructions, or other sensitive details in a public issue, pull request, discussion, event artifact, or appeal.
Use
GitHub private vulnerability reporting
when available. Otherwise use a private contact route listed on the
@BradGroux GitHub profile.
If a private route cannot be established immediately, retain the material safely and do not post it publicly.
Include only what is necessary to establish:
- the affected repository content, event, or release;
- the nature and likely consequence of the condition;
- whether sensitive material may already be public;
- safe reproduction or verification steps;
- containment already performed; and
- a private way to continue the report.
The founding steward or delegated maintainer will:
- acknowledge and contain the report through a private channel;
- preserve necessary evidence without unnecessarily copying sensitive material;
- assess affected content, versions, derivatives, events, and recipients;
- involve the appropriate privacy, security, legal, safety, rights, or other authority;
- correct, withdraw, rotate, or otherwise contain affected material;
- verify the correction and document the release effect; and
- coordinate any public disclosure so it does not increase harm.
No response-time guarantee, bug bounty, confidentiality contract, or safe-harbor term is created by this policy. Reporters and maintainers remain responsible for applicable law, authorization, professional duties, and organizational policy.