Skip to the content.

Security policy

AVP is a protocol specification, so “security issues” here mean weaknesses in the design or in the machine-readable artifacts that could lead implementers to build something insecure. Examples:

Vulnerabilities in a specific client, server, or library that implements AVP belong to that project, not here. Please report those to the relevant project.

Reporting

Please report security issues privately, not in a public issue or pull request.

Use GitHub’s private vulnerability reporting on this repository: open the Security tab and choose Report a vulnerability. That opens a private advisory visible only to you and the maintainers.

Include, as far as you can:

What to expect

This is a community project, so responses are best effort. We aim to acknowledge a report within a few days, agree on impact and a fix, and coordinate disclosure with you. Please give us reasonable time to publish a corrected version before disclosing publicly. Credit is given to reporters who want it.

Scope notes