Skip to content

Security: AgibotTech/sonic_for_a3

SECURITY.md

Security Policy

Reporting a Vulnerability

Report vulnerabilities in SONIC for A3 privately to this repository's maintainers through GitHub private vulnerability reporting. This entry is also available under Security → Advisories → Report a vulnerability. Do not post vulnerability details, exploit code, credentials, or private robot logs in a public issue.

If the private reporting entry is unavailable, open an issue requesting a private security contact, without including vulnerability details. Wait for the maintainers to provide a private channel before sharing the report.

Include the affected version or commit, impact, and minimal reproduction in the private report. Remove credentials and unrelated personal or robot data.

Upstream Issues

This A3 adaptation is maintained independently of the upstream GEAR team. For a vulnerability confirmed to affect unmodified upstream SONIC, follow upstream SONIC's security policy. A3-specific vulnerabilities should be reported to this repository's maintainers.

Maintainer Setup

Keep Private vulnerability reporting enabled in the repository security settings and verify that the report entry remains available. See GitHub's setup instructions.

There aren't any published security advisories