This policy covers security problems in the content-manager-design repository, its documentation tools, and its GitHub configuration. It does not cover a vulnerability in a client, a harmful mod archive, or a problem in index content.
Report a security problem through GitHub private vulnerability reporting. Do not open a public issue or disclose the details before the maintainers have had time to investigate and prepare a fix.
Include the affected files or workflow, the impact, and clear steps to reproduce the problem when you can. Use the public issue tracker for an ordinary documentation or process problem that does not put people, data, systems, or the content-manager process at risk.
- Report a vulnerability in Borea through Borea private vulnerability reporting.
- Report a harmful archive or an index listing problem through the content-index takedown form.
- Discuss a specification or process concern in content-manager-design Discussions.
The maintainers are volunteers and have no on-call rota. We aim to acknowledge a private report as soon as we can, but cannot guarantee a response or fix time. We will assess the report, keep the reporter informed when there is useful news, and prepare a fix before public disclosure when possible. Please coordinate public disclosure with us when possible.