Skip to content

Security: ntious/SynthDataHub

Security

SECURITY.md

Security policy

Supported content

Security reports are accepted for the current default branch. Because this repository primarily contains synthetic datasets, documentation, and analysis scripts, relevant reports include malicious or unsafe executable content, exposed credentials, dependency risks, privacy concerns, and data that appears to contain real personal or sensitive information.

Reporting a vulnerability

Do not disclose a suspected vulnerability or sensitive-data issue in a public GitHub issue. Use GitHub's private vulnerability-reporting feature when it is available. If that option is unavailable, contact the maintainer through the University of Cincinnati research profile and include:

  • the affected file or path;
  • a concise description of the issue and potential impact;
  • safe reproduction or verification steps; and
  • any suggested mitigation.

Do not include live credentials, personal data, or harmful payloads. Reports will be acknowledged and assessed as promptly as practical. Public disclosure should wait until a mitigation is available or a coordinated disclosure date has been agreed.

Research-use notice

Repository content is provided for research and education. Users remain responsible for validating data fitness, model behavior, privacy requirements, licenses, and domain-specific risks before operational use.

There aren't any published security advisories