If you discover a security vulnerability in any Really Artificial project, please report it responsibly.
Report in the specific project's security tab:
Send an email to harsh.joshi.pth@gmail.com with:
- Which Really Artificial project is affected
- Type of issue
- Full paths of source file(s) related to the issue
- Step-by-step instructions to reproduce
- Impact of the issue
- Response Time: Response within 48 hours
- Acknowledgment: Confirmation and next steps
- Updates: Progress tracking
- Disclosure: Coordinated disclosure timeline
All Really Artificial projects follow these security principles:
- No Dynamic Code Execution: No eval() or similar
- Input Validation: All inputs validated before processing
- Dependency Updates: Regular security patches
- Audit Logging: Security-relevant actions are logged
- Principle of Least Privilege: Minimal permissions by default
For general security questions: open a discussion in the relevant project repository.
Thank you for helping keep Really Artificial projects and their users safe!