Skip to content

Security: neotree/.github

SECURITY.md

Security Policy

Neotree builds clinical software used in neonatal care. We take security reports seriously and will work with you in good faith to resolve them.

Reporting a vulnerability

Please do not open a public issue for a security problem.

Use one of these channels instead:

  1. GitHub private vulnerability reporting — preferred. Go to the Security tab of this repository and choose Report a vulnerability. This opens a private thread visible only to Neotree maintainers.

  2. Emailsecurity@neotree.org

If you are reporting something time-critical and have had no response, say so in the subject line.

What to include

Whatever you have. A report is useful even if it is incomplete. If you can, tell us:

  • which repository, branch and file
  • what you observed, and how you found it
  • what an attacker could do with it
  • anything that would help us reproduce it

If you have found something in a deployed Neotree service rather than in source code, please tell us that explicitly — the response is different and more urgent.

What to expect from us

Acknowledgement we aim to reply within 3 working days
Initial assessment we aim to come back to you within 10 working days
Progress updates we aim to update you at least every 14 days while a report is open

Neotree is a small charity and these are intentions rather than guarantees. If you have not heard from us and the matter is urgent, please say so — we would rather be chased than leave a report sitting.

We will tell you what we found, what we are doing about it, and when it is fixed. If we disagree that a report is a security issue, we will explain why rather than close it silently.

Scope

In scope: source code in this GitHub organisation, and the build and release process for it.

Out of scope: findings that require physical access to a device, social engineering of Neotree staff or partner clinicians, or denial of service.

Patient data. Neotree systems process sensitive health information. If you believe you have accessed real patient data, stop, do not copy or retain it, and tell us immediately. We will not pursue you for an accidental discovery that is reported promptly and handled this way.

Disclosure

We ask that you give us a reasonable opportunity to fix an issue before publishing. We will not ask you to stay quiet indefinitely, and we are happy to credit you when the fix ships unless you would rather we did not.

Supply chain

Neotree publishes no packages to npm, PyPI or any other registry. Any package claiming to be an official Neotree distribution is not one, and we would be grateful to hear about it.

There aren't any published security advisories