Skip to content

Security: RebuildingAmerica/atlas

SECURITY.md

Security Policy

Please do not report vulnerabilities, exposed secrets, private data, or sensitive personal information in public issues, pull requests, discussions, or comments.

Reporting A Vulnerability

Use GitHub's private vulnerability reporting flow:

https://github.com/RebuildingAmerica/atlas/security/advisories/new

If that flow is unavailable, email contact@rebuildingus.org with the subject Atlas security report. Do not include secrets, tokens, or sensitive personal information in the subject line.

What To Report Privately

  • Authentication, authorization, or session issues.
  • Exposed API keys, tokens, credentials, or secrets.
  • Sensitive data exposure in logs, fixtures, exports, screenshots, or generated files.
  • Vulnerabilities in hosted Atlas, self-hosting defaults, API behavior, MCP behavior, Scout, or dependency supply chain.
  • Bugs that could let someone alter, impersonate, or misrepresent a real person or organization in Atlas data.

What To Include

  • A short description of the issue.
  • Steps to reproduce, if safe to share privately.
  • The affected URL, command, package, or component.
  • Any public-safe logs or screenshots.
  • Whether the issue affects hosted Atlas, self-hosted deployments, local development, or all of them.

Public Follow-Up

Maintainers will coordinate disclosure based on severity, exploitability, and the risk to users or people represented in Atlas data. Public follow-up should avoid secrets, private data, and sensitive personal information.

There aren't any published security advisories