Please don’t open public GitHub issues or pull requests for security problems.
If you think you’ve found a security vulnerability in this project (the Zed extension for Colab), report it privately so we can look into it and fix it without exposing details right away.
Please use GitHub’s private reporting:
- Go to the repo’s main page.
- Click the “Security” tab.
- Click “Report a vulnerability” and follow the prompts.
If that option isn’t available in your view of the repo, please don’t share details publicly. In that case, you can stop there or try to reach out via whatever contact method is listed in the repo (if any).
It helps a lot if you can share:
- What the issue is and where you found it
- Steps to reproduce it
- What you think the impact might be
- Any logs, stack traces, or proof-of-concept snippets
When you report a vulnerability:
- We’ll read it and try to reproduce the issue.
- If it’s valid, we’ll work on a fix and a release.
- Once it’s fixed, we may publish a short summary. If you’d like to be credited, say what name/handle to use.
This policy is only for this repository and its code.
It does not cover:
- Google Colab itself
- Google accounts or infrastructure
- Any other Google or third-party services
If the problem looks like it affects Google Colab or Google services in general, please use Google’s official security reporting instead.