The AwareRide team takes security seriously. If you discover a security vulnerability in any AwareRide repository, please report it privately — do not open a public issue.
How to report:
- Email: security@awareride.org
- Subject line:
[SECURITY] <brief description>
We will acknowledge receipt within 48 hours and will work with you to:
- Confirm and assess the reported issue.
- Coordinate a fix and coordinated disclosure timeline.
- Credit you for the discovery (if you wish to be credited).
This policy applies to all public repositories under the AwareRide organization.
- Issues already reported in public GitHub issues or discussions.
- General feature requests or non-security bug reports (please use GitHub Issues/Discussions for those).
We ask that you allow us a reasonable period (typically 90 days) to fix and release a patch before public disclosure.
Thank you for helping keep AwareRide and its community safe.