If you discover a security vulnerability in any of the Meyer Lab's repositories, please report it privately rather than opening a public issue.
Email github-public@asmlab.org with:
- The affected repository and, if known, the commit or version
- A description of the vulnerability and its potential impact
- Steps to reproduce, if possible
We'll acknowledge your report within a few business days. Most of our repositories are research codebases rather than production services, so response times and remediation may vary depending on severity and active development status, but we take all reports seriously.
Our repositories are actively developed research code without a formal long-term-support policy. Fixes are generally applied to the latest commit on each repository's default branch rather than backported to prior releases.
This policy applies to any meyer-lab repository that does not define its own SECURITY.md.