Skip to content

Security: fernando-ace/Auburn-Academic-Planner

Security

SECURITY.md

Security policy

Supported release

Only the latest deployed release is supported. Auburn Academic Planner is currently an independent student-built pilot, not an official or Auburn-endorsed service.

Do not disclose sensitive information publicly

Do not open a public GitHub issue containing a vulnerability, credential, student record, Degree Works document, name, student ID, or other private information. The public issue form is limited to non-sensitive product and accessibility feedback.

GitHub private vulnerability reporting is not yet enabled for this repository. Repository administrators must enable it and verify notification coverage before any sponsored campus use. Until a private channel is available, do not submit sensitive report details through this repository or the application.

Operator response expectations

Before a sponsored pilot, the operator and Auburn should document a private incident contact, severity and response targets, vendor-escalation paths, retention expectations, and FERPA review. Suspected credential exposure should be rotated immediately through the affected provider rather than posted in an issue.

There aren't any published security advisories