This repository contains static fixture data for dependency-discovery testing. It is not intended to be deployed as an application or service.
Security reports for this repository should focus on issues such as:
- accidental inclusion of sensitive information
- malicious or unsafe repository content introduced by mistake
- documentation or workflow guidance that would create a real security risk for contributors
Do not use this repository's security reporting channel for:
- known or suspected vulnerabilities in third-party packages referenced by the fixtures
- advisories affecting package versions intentionally included as fixture data
- claims that a fixture contains an old or vulnerable dependency by design
Those topics are expected outcomes of the test corpus and should be handled by the relevant upstream maintainers, registries, or advisory sources where appropriate.
If you believe the repository itself has a legitimate security issue, contact the maintainers privately before opening a public issue.
A useful report should include:
- a clear description of the issue
- the affected file or directory
- the impact
- any suggested remediation
Please avoid publishing a full public report until maintainers have had a reasonable opportunity to review and address the issue.