This policy applies by default across the UCT Department of Electrical Engineering GitHub organisation. Individual repositories may provide their own SECURITY.md, which takes precedence for that repository.
Please report security vulnerabilities privately. Do not open a public issue, as that would disclose the problem before it can be addressed.
You can report a vulnerability by either:
- Using GitHub's private vulnerability reporting, through the Security tab of the affected repository, where it is enabled.
- Emailing the organisation administrators at [eeesoftware@uct.ac.za].
Please include enough detail to reproduce the issue, along with any relevant repository, version or environment information.
- We will acknowledge your report, ordinarily within a few working days.
- We will investigate and keep you informed of progress.
- Once resolved, we are happy to credit you for the report, unless you would prefer to remain anonymous.
Much of what this organisation hosts is teaching and research material that is not run in a security-sensitive setting. This policy matters most for repositories that others depend on or execute, such as public tools and libraries. If in doubt, please report anyway.