This project supports responsible disclosure of security vulnerabilities and adheres to the FINOS Security Vulnerabilities Responsible Disclosure Policy. If you believe you have found a security vulnerability in this project, we encourage and appreciate your report. Please report it privately using one of the methods below — do not open a public GitHub Issue or otherwise disclose it publicly.
- GitHub private vulnerability reporting (preferred): Use the "Report a vulnerability" button under this repository's Security tab. This opens a private advisory and communication channel with the maintainers.
- Email: If you're unable to use GitHub's private reporting, email calm-maintainers@lists.finos.org and security@finos.org with a description of the issue.
- Report the vulnerability privately using one of the methods above.
- The project team will acknowledge receipt, triage the report, and — if confirmed — work with you to investigate and develop a fix.
- Once a fix is available, it will be released and the vulnerability will be publicly disclosed in accordance with the FINOS Security Vulnerabilities Responsible Disclosure Policy.
Thank you for helping keep FINOS projects and their users secure.