Please do not report security vulnerabilities through public GitHub issues.
For security-sensitive reports, first use the private security contact listed in the relevant project repository. If the repository does not publish one, email the DataSys organization owners at shuhao_zhang@hust.edu.cn. Include:
- The affected repository and version or commit.
- A clear description of the issue.
- Reproduction steps or proof-of-concept details, when safe to share.
- Any known impact on users, deployments, data, credentials, or infrastructure.
Maintainers should acknowledge security reports promptly and coordinate responsible disclosure before public discussion.