| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This policy applies to every repository in the DI-PASSIONATE organisation, unless a repository ships its own SECURITY.md, which then takes precedence.
Please do not open a public issue, pull request or discussion for a security problem.
Report it privately instead, in either of these ways:
Please include:
If you need to send something confidential, say so in your first message and we will arrange a channel.
We are a publicly funded research project, not a vendor with an on-call rotation, so we answer in working days rather than hours:
| Stage | Target |
|---|---|
| Acknowledgement of your report | within 5 working days |
| Initial assessment and severity | within 10 working days |
| Fix or documented mitigation | depends on severity and complexity; we will keep you updated |
We will tell you what we conclude, credit you in the advisory if you would like to be credited, and coordinate the disclosure date with you. We ask that you give us a reasonable opportunity to fix the issue before making it public. We do not operate a bug bounty and cannot offer payment.
These are research tools under active development. Security fixes go into the default branch and the next release only - there are no long-term support branches, and we do not backport to older tags. If you are running an older version, the fix is to update.
Please read this before reporting: it tells you what we consider a vulnerability.
Our tools are local design and simulation tools. They are meant to be run by an engineer on their own workstation or compute node, on inputs that engineer trusts. They are not network services, they have no authentication or multi-tenancy, and they are not designed to sandbox hostile input.
Consequently, the following are expected behaviour and not vulnerabilities:
We are interested in, and will treat as vulnerabilities:
We integrate several third-party tools and do not maintain them. A vulnerability in Xyce, AWS Palace, gmsh, Qucs-S, ONNX Runtime or any other dependency should be reported to that project.
| Back | FazBrowse Home | New Git URL |