Skip to content

Security: gslhub/benchmarks

Security

SECURITY.md

Security Policy

Security matters to GSLHub because the project combines public software, research workflows, administrative tooling and preserved research artifacts.

Reporting a vulnerability

Please do not open a public GitHub issue for a vulnerability that could expose credentials, authentication weaknesses, private research data, administrative access, infrastructure details or other sensitive information.

Instead, report the issue privately to:

research@gslhub.com

Use the subject line [SECURITY] GSLHub vulnerability report and include, where possible:

  • the affected repository, component or URL;
  • a clear description of the issue;
  • steps to reproduce it;
  • the potential security impact;
  • any relevant logs, screenshots or proof-of-concept details that can be shared safely;
  • a suggested mitigation, if known.

Please avoid including real credentials, personal data or unnecessary sensitive information in the report.

Responsible disclosure

We ask reporters to allow reasonable time for investigation and remediation before publishing vulnerability details. We will aim to acknowledge legitimate reports and coordinate disclosure when appropriate.

GSLHub does not currently operate a public bug-bounty program and cannot guarantee monetary rewards.

Supported code

Security fixes are prioritized for the current public platform and actively maintained branches. Historical branches, archived releases and third-party dependencies may require separate upstream remediation.

Research and data concerns

If the issue concerns research integrity, accidental disclosure of non-public research material, private datasets, preserved artifacts or methodological controls rather than a software vulnerability, use the same contact address and clearly identify it as a research-data or integrity concern.

There aren't any published security advisories