Skip to content

Security: Oraclizer/.github

Security

SECURITY.md

Security policy

This file is the fallback security policy for Oraclizer repositories that do not define a repository-specific SECURITY.md. A policy in the affected repository takes precedence.

Report sensitive concerns privately

For the repository affected by the concern:

  1. Open its Security tab.
  2. Select Advisories.
  3. Select Report a vulnerability.

If Private Vulnerability Reporting is unavailable, email jay@oraclizer.io with the subject ORACLIZER SECURITY. Identify the affected repository and exact commit. Do not include unrelated secrets, personal data, production credentials, or confidential third-party material.

Do not disclose exploit details in a public issue, Pull Request, discussion, standards forum, research review, or social post before coordinated disclosure.

Public reports

Broken links, documentation defects, reproducibility failures, overly strong claims, non-sensitive counterexamples, and model-scope concerns may use the affected repository's public issue forms.

When possible, include the exact repository, commit, path, tool version, minimal reproduction, expected result, and observed result.

Handling boundary

The maintainer will assess scope and may request additional information. No response time, remediation time, disclosure date, bounty, safe-harbor term, financial reward, audit conclusion, or service-level commitment is promised by this policy.

A public repository or passing workflow does not establish the security of an implementation, deployment, network, cryptographic system, legal process, or modified fork. The affected repository's license and explicit assurance boundary remain controlling.

There aren't any published security advisories