This repository is public, but the service it supports is intended for internal HMCTS and justice users.
If you discover a security vulnerability in this repository or the service, do not report it in a public GitHub issue, pull request, comment or discussion.
Report vulnerabilities using the HMCTS Vulnerability Disclosure Policy:
https://www.gov.uk/guidance/hmcts-vulnerability-disclosure-policy
When reporting a vulnerability, please include:
- a summary of the issue
- steps to reproduce
- affected page, route, component or service
- potential impact
- any suggested mitigation, if known
Please allow time for the issue to be investigated and fixed before making any public disclosure.
Do not include secrets, credentials, personal data or exploit details in public channels.
This policy applies to all code and configuration in this repository, including:
- application code
- frontend assets and routing
- CI/CD and deployment configuration
- third-party packages and dependencies
Security updates are applied to supported versions of the service.
Repository maintainers will triage reported vulnerabilities and work with the appropriate HMCTS and platform security teams where needed.