This policy covers this repository, its documentation website, dependencies, and automation. Security fixes target the current main branch; older revisions are not maintained separately.
Report vulnerabilities in listed third-party projects directly to their maintainers. If a catalog link has become malicious or compromised, notify us privately too. Ordinary broken links and factual corrections can be reported through public issues.
Email opensourceresporting.ai@proton.me with the subject Security report: awesome-physical-ai. Do not disclose vulnerabilities, credentials, or exploit details in public issues or pull requests.
Include:
- The affected file, URL, dependency, or workflow, and commit or version if known.
- A description of the issue, potential impact, and safe reproduction steps.
- Redacted evidence and any suggested mitigation.
Avoid accessing others' data or disrupting services when investigating. Never include live secrets or unnecessary personal information in a report.
Maintainers will assess the report, request clarification if needed, and coordinate remediation and disclosure with the reporter. Response and fix times depend on availability and severity; no fixed timeline is guaranteed. Please coordinate public disclosure so maintainers have an opportunity to address the issue.