Please do not report security vulnerabilities through public GitHub issues.
We use GitHub Security Advisories for responsible disclosure. This keeps the report private until a fix is ready and gives you credit for the discovery.
- Go to the Security tab of this repository.
- Click "Report a vulnerability" — or go straight to
https://github.com/npci/ainxt-enterprise/security/advisories/new. - Fill in the advisory form with as much detail as possible.
The report stays confidential between you and the maintainers until a fix is published, and GitHub handles CVE assignment if one is warranted.
Security contact:
opensource@npci.org.in(monitored group address — seeMAINTAINERS.md). Use GitHub Security Advisories (above) for all vulnerability reports — this keeps the report confidential and enables CVE assignment. The email address is provided as a secondary contact only.Response SLA: We acknowledge all vulnerability reports within 5 business days and aim to provide an initial assessment within 10 business days.
A good vulnerability report includes:
- Description — what the vulnerability is and its potential impact.
- Steps to reproduce — a minimal, reliable reproduction path.
- Affected component — which service, file, or endpoint is affected.
- Suggested fix — optional, but appreciated.
- Your contact details — so we can keep you updated and credit you.