Skip to content

Security: hkn-alpha/PHASE

Security

SECURITY.md

Security

The PHASE team takes the security of this project and its services seriously. Thanks for helping to make PHASE secure for everyone.

Reporting a vulnerability

If you believe you have found a vulnerability in any PHASE software, please see if its in scope with a general PrairieLearn vulnerability. If this is the case, please report it to PrairieLearn and consult their SECURITY.md.
If you believe its scope is limited to this project, please report it to us via coordinated disclosure. Do not report suspected vulnerabilities publicly, including through GitHub issues or public Slack channels. Instead, please send an email to hkn@illinois.edu with as much relevant information as possible, including:

  • The type of issue (e.g. SQL injection or cross-site scripting)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Impact of issue, including how an attacker might exploit the issue

The PHASE team @ HKN Alpha's SSC will triage your report and respond according to its impact on PHASE users and systems.

There aren't any published security advisories