Skip to content

Security: lysyloxidase/KneeMechBridge

Security

SECURITY.md

Security policy

KneeMechBridge is research software. It is not intended or validated for diagnosis, treatment, triage, patient-specific clinical decisions, or operation as a clinical service. The repository accepts no identifiable patient data.

Supported code

Before the first release, security fixes target the default development branch. After publication, fixes target the latest tagged release and that branch. Older snapshots may receive a fix only when practical. Dependency alerts are assessed for whether the affected dependency and code path are actually used by this project.

Reporting a security vulnerability

Report vulnerabilities in the code, command-line tools, dashboard, packaging, or dependencies privately. After the public repository enables GitHub private vulnerability reporting, use Security > Report a vulnerability. If that option is not available, open only a minimal public issue asking the maintainers to establish a private channel. Do not include exploit details, credentials, private paths, or sensitive data in that issue.

Include the affected version or commit, environment, reproduction steps, likely impact, and any suggested mitigation. Use synthetic inputs only. Maintainers will acknowledge and assess reports on a best-effort basis; this research project does not promise a fixed response or disclosure schedule.

Scientific inaccuracies, questionable assumptions, unit errors, and provenance or validity-domain concerns are not normally security vulnerabilities. Report those with the public scientific/model issue template unless the report itself would expose a security weakness or sensitive information.

There aren't any published security advisories