Security fixes are applied to the current main branch. This repository is a portfolio prototype, not a production academic-advising service.
Please do not open a public issue for a suspected vulnerability. Email ethmoon@umich.edu with the subject AcademiQ security report and include:
- the affected route, component, or dependency;
- steps to reproduce the issue;
- the likely impact; and
- any suggested mitigation.
Do not include real student records, passwords, access tokens, or other sensitive data in a report. You can expect an acknowledgment within seven days.