mathlib is a library of formalized mathematics, and it contains many supporting tactic metaprograms, scripts for tooling and maintenance as well as CI workflows. The maintainers are devoted to keeping all of the above free of security issues to protect our contributors and users. Thank you for doing your part to keep mathlib secure by reporting issues in a responsible way.
If you believe you have found a security vulnerability in mathlib, please report it using GitHub's private vulnerability reporting. If you do not have a GitHub account, you may also send an email to security@mathlib.org. Please do not report security issues in public settings, e.g. GitHub or Zulip. If you have questions about this policy, please ask in this Zulip thread.
Please include sufficient information to help us to understand the issue, including (as much as you can provide of) the following:
- the type of issue
- full paths to any related source files
- the affected branches, tags, or commit SHAs
- any details required to reproduce the issue, e.g. OS, configuration, etc. (if applicable)
- proof-of-concept or exploit code
- the impact of the issue and how the issue can be exploited
The maintainers will reply with a message acknowledging the receipt of your report within 2 business days and then respond to the details of your report within 1 week. The times quoted here are subject to change, but we will attempt to keep this text up-to-date.