Skip to content

Security: MarrowGlass/orders

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Public Issues and Discussions are not the place to report security vulnerabilities or to share sensitive details. Anything posted here is public and indexed.

If you believe you have found a security issue in a MarrowGlass system, report it privately using GitHub's private vulnerability reporting:

Report a security vulnerability →

When reporting, include enough detail to reproduce the problem without exposing real systems or real users.

What not to post publicly

Never publish, in an Issue, Discussion, or advisory draft, any of the following:

  • credentials, passwords, API keys, tokens, or connection strings
  • exploit details that could be used against a live client system before a fix is available
  • private source code you do not have the right to share
  • database contents or records tied to real people
  • customer data, even when redacted carelessly

Preparing demonstrations

If a demonstration is needed to make a report clear:

  • Use a throwaway environment you control, not a production system.
  • Sanitize every example. Replace real names, emails, tokens, and identifiers with clearly fake values.
  • Provide reproduction steps that work against the demonstration, not against a live system.
  • Prefer screenshots with redaction over raw dumps.

Scope

This policy covers the intake process and the systems MarrowGlass operates for clients. Reports about third-party dependencies should be filed with the upstream maintainer; we will coordinate where we are responsible.

What to expect

We acknowledge private reports, prioritize based on impact and exploitability, and coordinate disclosure with you. We do not publish a public security email address on this page — private vulnerability reporting on GitHub is the intended channel.

There aren't any published security advisories