ToolGlot takes security reports seriously.
Please do not open a public GitHub issue for suspected vulnerabilities.
Use one of these private channels instead:
- Open a private GitHub vulnerability report: GitHub Security Advisory
- If the advisory flow is unavailable, open a private maintainer contact via GitHub profile: @SohamDutta
Please include:
- affected version/commit
- clear reproduction steps
- expected vs actual behavior
- impact assessment
- any suggested remediation
- Acknowledgement: within 72 hours
- Initial triage: within 7 calendar days
- Fix or mitigation plan: within 30 calendar days for confirmed issues
Complex vulnerabilities may require more time. We will provide status updates in the advisory thread.
- We confirm and triage the report privately.
- We prepare and validate a fix.
- We publish a patched release and advisory.
- We credit the reporter (if requested).
ToolGlot runs OpenSSF Scorecard in CI.
If a Scorecard check fails or regresses:
- Open a GitHub issue labeled
area:securityandpriority:P1. - Include the failed check name, workflow link, and remediation plan.
- Link the issue in the remediation commit/PR.