The GTT Project takes the security of our software seriously, which includes all source code repositories managed through our GitHub organization.
If you believe you have found a security vulnerability in any GTT Project-managed repository, please report it to us as described below.
Please do not report security vulnerabilities through public GitHub issues or discussions.
Instead, please use GitHub's private vulnerability reporting: open the Security tab of the affected repository and choose Report a vulnerability. This creates a private advisory that only you and the maintainers can see. See GitHub's documentation on privately reporting a security vulnerability for details.
If you cannot use GitHub's private reporting, you can also reach us by email at hello@gtt-project.org.
Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:
- Type of issue (e.g. SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
This information will help us triage your report more quickly.
We prefer all communications to be in English.