This repository is actively maintained on the default development branch and on any deployment branch currently used by the Department of Biodiversity, Conservation and Attractions.
Security fixes are prioritised for:
- the default branch
- currently supported deployment branches
Older branches may receive fixes at the maintainers' discretion.
Do not report security vulnerabilities through public GitHub issues, pull requests, or discussion threads.
Please report suspected vulnerabilities privately to the maintainers responsible for this service using the following contact channel:
ecoinformatics.admin [at] dbca [dot] wa [dot] gov [dot] au
Replace [at] with @ and each [dot] with . before sending.
When reporting, include:
- a clear description of the issue
- the affected component or feature
- reproduction steps or a proof of concept, where safe to provide
- the potential impact
- any suggested mitigation or fix, if known
The maintainers will aim to:
- acknowledge receipt of the report
- assess severity and impact
- coordinate remediation and release timing
- provide a responsible disclosure path where appropriate
If you are unsure whether an issue is security-sensitive, report it privately first.
See README.md for the documentation index.