This file is the fallback security policy for Oraclizer repositories that do
not define a repository-specific SECURITY.md. A policy in the affected
repository takes precedence.
For the repository affected by the concern:
- Open its Security tab.
- Select Advisories.
- Select Report a vulnerability.
If Private Vulnerability Reporting is unavailable, email
jay@oraclizer.io with the subject ORACLIZER SECURITY. Identify the affected
repository and exact commit. Do not include unrelated secrets, personal data,
production credentials, or confidential third-party material.
Do not disclose exploit details in a public issue, Pull Request, discussion, standards forum, research review, or social post before coordinated disclosure.
Broken links, documentation defects, reproducibility failures, overly strong claims, non-sensitive counterexamples, and model-scope concerns may use the affected repository's public issue forms.
When possible, include the exact repository, commit, path, tool version, minimal reproduction, expected result, and observed result.
The maintainer will assess scope and may request additional information. No response time, remediation time, disclosure date, bounty, safe-harbor term, financial reward, audit conclusion, or service-level commitment is promised by this policy.
A public repository or passing workflow does not establish the security of an implementation, deployment, network, cryptographic system, legal process, or modified fork. The affected repository's license and explicit assurance boundary remain controlling.