Last editorial review:
Security policy.
How to report vulnerabilities affecting NDT digital projects and services.
Responsible private reporting helps NDT digital investigate and address security risks.
This is a translation provided for convenience. The Portuguese version is the binding one, and it prevails in case of any divergence.
Report a vulnerability privately
Send security reports to security@ndtdigital.com.br or use GitHub Private Vulnerability Reporting when it is enabled for the affected repository.
Do not publish vulnerability details in issues, discussions, pull requests, or social media.
What to include
Include the affected project or service, version when known, a clear description, reproduction steps, observed impact, and relevant evidence. Do not include credentials or unrelated personal data.
Scope and supported versions
This policy covers software, repositories, services, APIs, websites, and infrastructure maintained by NDT digital. Project-specific security policies take precedence.
Actively maintained projects and supported versions receive priority for security fixes.
Response and responsible disclosure
NDT digital may validate the report, assess impact, prepare mitigation, and coordinate disclosure. Timing depends on severity, complexity, and operational risk.
Give NDT digital a reasonable opportunity to investigate before publishing sensitive details, and limit testing to what is necessary to demonstrate the issue safely.
Third-party components
NDT digital products may depend on third-party software, libraries, or infrastructure. When the flaw sits only in an external component, remediation may involve updating dependencies, changing configuration, or coordinating with the upstream project. Reports about an NDT product's exposure remain relevant.