ValidationHub's code is public, while operational evidence is permissioned-by-default. The repository must not receive secrets, credentials, patient data, confidential partner/customer data, proprietary constructs, raw sequence data, respondent identity, or exact confidential process parameters.
Do not report security issues by attaching private wet-lab records or confidential validation data. Use the minimum non-sensitive technical detail needed to describe the issue.
Report suspected software vulnerabilities privately through GitHub Security Advisories.