Please do not report vulnerabilities, exposed secrets, private data, or sensitive personal information in public issues, pull requests, discussions, or comments.
Use GitHub's private vulnerability reporting flow:
https://github.com/RebuildingAmerica/atlas/security/advisories/new
If that flow is unavailable, email
contact@rebuildingus.org with the subject
Atlas security report. Do not include secrets, tokens, or sensitive personal
information in the subject line.
- Authentication, authorization, or session issues.
- Exposed API keys, tokens, credentials, or secrets.
- Sensitive data exposure in logs, fixtures, exports, screenshots, or generated files.
- Vulnerabilities in hosted Atlas, self-hosting defaults, API behavior, MCP behavior, Scout, or dependency supply chain.
- Bugs that could let someone alter, impersonate, or misrepresent a real person or organization in Atlas data.
- A short description of the issue.
- Steps to reproduce, if safe to share privately.
- The affected URL, command, package, or component.
- Any public-safe logs or screenshots.
- Whether the issue affects hosted Atlas, self-hosted deployments, local development, or all of them.
Maintainers will coordinate disclosure based on severity, exploitability, and the risk to users or people represented in Atlas data. Public follow-up should avoid secrets, private data, and sensitive personal information.