Please report security vulnerabilities through GitHub's private vulnerability reporting. This ensures the report reaches the maintainers directly and allows us to collaborate on a fix before public disclosure. We aim to acknowledge reports within 7 business days.
To help us triage and reproduce the issue, please include:
- Affected component (e.g. module, class, or API)
- Description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- Any relevant environment details (Scio version, runner, JDK version)
This policy covers only the Scio library itself. Vulnerabilities in upstream dependencies such as Apache Beam should be reported to the Apache Security Team.
If you have questions about a potential vulnerability, you can also reach out to the maintainers via GitHub Discussions.
Reports are triaged by the maintainers. Confirmed vulnerabilities are handled through GitHub Security Advisories:
- A fix is developed in a private fork, keeping the vulnerability details confidential until a patch is available.
- The fix is released in a new version of Scio.
- The security advisory is published with credit to the reporter.