If you believe you have found a security vulnerability in a dyalog-labs project, please do not open a public issue.
Send a report to security@dyalog.com with:
- The repository and version affected.
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof of concept.
We will acknowledge receipt within five working days and provide an estimate for a fix or mitigation once we have assessed the report.
This policy covers code published in the dyalog-labs organisation. For vulnerabilities in Dyalog APL itself or other commercially supported Dyalog products, please contact Dyalog support through the usual channels.