No stable GitHub release has been published yet. Security fixes target the
current main branch and will be included in the next applicable release.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository:
https://github.com/openbimrs/ifc/security/advisories/new
Include, where possible:
- the affected commit or package version;
- the smallest safe reproduction;
- the security impact and expected trust boundary;
- whether malformed IFC, STEP, XML, archive, or schema input is involved;
- any suggested mitigation.
Do not upload confidential building models or standards material that you do not have the right to share. A reduced synthetic fixture is preferred.
The maintainers will keep the report private while it is assessed and will coordinate disclosure after a fix or mitigation is available. No response-time SLA is currently promised.
The same private form is also the project's confidential conduct-reporting
channel. Prefix non-security reports with [Conduct] and follow the
Code of Conduct.