The Pact Community Organization takes the security of our software seriously. Thank you for helping keep our users safe by disclosing vulnerabilities responsibly.
This is the organization-wide default policy. A repository may publish its own
SECURITY.md, which takes precedence for that repository.
Do not report security vulnerabilities through public GitHub issues, Discussions, or pull requests.
Instead, report them privately through a GitHub Security Advisory:
- Go to the affected repository's Security tab.
- Click Report a vulnerability (Private vulnerability reporting).
- Or email info@pact-community.org with the details below.
Please include:
- Type of issue (e.g. prompt injection, privilege escalation, data exfiltration, supply-chain, path traversal, command injection).
- Affected repository, component, and version or commit.
- Step-by-step reproduction or proof of concept (only if safe to share).
- Impact assessment (what an attacker could achieve).
- Any suggested mitigation.
- We will acknowledge your report within 3 business days (best effort).
- We will provide an assessment and expected timeline after triage.
- We will keep you informed as we work on a fix.
- We will credit you in the advisory unless you prefer to remain anonymous.
We support good-faith security research. If you make a good-faith effort to comply with this policy, we will consider your research authorized, work with you to understand and resolve the issue quickly, and will not pursue or support legal action against you.