Skip to content

Security: Lab10YR/.github

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest commit on the default branch only.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Contact: info@lab10yr.com Subject line: [SECURITY] <brief description>

We acknowledge receipt within 48 hours and provide a resolution timeline within 7 business days.

Please include:

  • Affected repository and file(s)
  • Steps to reproduce
  • Potential impact
  • Suggested mitigation, if known

Scope

Repository In Scope
NRCS-Soil-Data-Access XSS in SQL explorer, SSRF via SDA proxy, data injection
Soil-Data-Access-Training-Resources XSS in Query Lab, unsafe eval() usage

Out of Scope

  • Third-party services (USDA SDA API, GitHub Pages, Cloudflare)
  • Denial of service attacks
  • Social engineering

Disclosure

Once a fix is deployed we publish a brief advisory in the affected repository's Security tab.

There aren't any published security advisories