Skip to content

Security: kegouro/spmkit

Security

SECURITY.md

Security and private scientific data

Report a software vulnerability through GitHub’s private security-reporting surface when available. Do not open a public issue containing exploit details, credentials, private paths, or restricted instrument data.

For parser crashes involving a confidential file, provide a minimal synthetic reproducer whenever possible. If the original file is necessary, first describe its format, checksum, size, redistribution status, and the safest lawful transfer route. Maintainers will not request that restricted data be posted publicly.

SPM-Kit is research software, not a security boundary. Treat instrument files, plugins, recipes, and project files as untrusted input and work on copies.

There aren't any published security advisories