Skip to content

Security: BradGroux/ai-dev-days

SECURITY.md

Security and Sensitive-Disclosure Policy

Purpose

This policy provides a private route for reporting credentials, personal or confidential information, unsafe publication, malicious repository behavior, or another security-sensitive condition affecting AI Dev Days.

It complements the Code of Conduct, contribution SOP, and publication-safety guidance.

Supported Versions

The latest approved release and the default branch receive security-sensitive corrections. Historical event packets may be corrected when the consequence warrants it even if their tool guidance is otherwise preserved as point-in-time material.

Report Privately

Do not place credentials, personal information, private evidence, attendee or client data, exploit instructions, or other sensitive details in a public issue, pull request, discussion, event artifact, or appeal.

Use GitHub private vulnerability reporting when available. Otherwise use a private contact route listed on the @BradGroux GitHub profile.

If a private route cannot be established immediately, retain the material safely and do not post it publicly.

Include only what is necessary to establish:

  • the affected repository content, event, or release;
  • the nature and likely consequence of the condition;
  • whether sensitive material may already be public;
  • safe reproduction or verification steps;
  • containment already performed; and
  • a private way to continue the report.

Response and Disclosure

The founding steward or delegated maintainer will:

  1. acknowledge and contain the report through a private channel;
  2. preserve necessary evidence without unnecessarily copying sensitive material;
  3. assess affected content, versions, derivatives, events, and recipients;
  4. involve the appropriate privacy, security, legal, safety, rights, or other authority;
  5. correct, withdraw, rotate, or otherwise contain affected material;
  6. verify the correction and document the release effect; and
  7. coordinate any public disclosure so it does not increase harm.

No response-time guarantee, bug bounty, confidentiality contract, or safe-harbor term is created by this policy. Reporters and maintainers remain responsible for applicable law, authorization, professional duties, and organizational policy.

There aren't any published security advisories