Skip to content

Security reporting ​

DASP is a draft specification. This repository does not yet provide a released host or client package.

Report non-sensitive specification defects through a specification issue.

For a security issue with sensitive details, use GitHub private vulnerability reporting when it is enabled for this repository. If that option is unavailable, open an issue requesting a private contact without including exploit details, credentials, or private data. Maintainers will provide a reporting route. No response time is promised.

State the source commit, affected requirement or component, conditions needed to reproduce the issue, and potential impact. The security requirements describe the protocol trust boundary.