Do not report suspected vulnerabilities through public issues.
Report them privately through GitHub's private vulnerability reporting for this repository, or email pews@rcpch.ac.uk.
Include a description of the issue and impact, affected versions or commit hashes, safe reproduction steps, and any suggested mitigation. Redact credentials and patient-identifiable or other sensitive data.
We aim to acknowledge reports within 2 working days and provide a substantive response within 5 working days.
This policy covers this repository. Report upstream dependency vulnerabilities to the relevant maintainer and notify us privately if they affect this project.
If the issue could affect patient safety, clinical workflow, or patient-identifiable data, flag that clearly. We will triage it as both a security finding and a potential safety hazard.
We use coordinated disclosure. After a fix is available, we will publish an appropriate advisory or release note and credit the reporter if they agree.