Status: Current Last updated: 2026-09-06
Please do not report security issues in public GitHub issues, pull requests, discussions, or commit messages.
Preferred reporting channels:
- GitHub private vulnerability reporting for
TalkBank/batchalign - Email franklinchen@franklinchen.com
Please include:
- the affected Batchalign command, engine, application, or other repository path
- the commit SHA, branch, or released version you tested
- reproduction steps or a proof of concept
- impact assessment
- any suggested remediation or mitigation
We will acknowledge reports, investigate them privately, and coordinate a fix and disclosure plan before public discussion when the report is validated.
For security triage, please report the issue against one of these:
- the current
mainbranch, or - the latest tagged release for the affected public surface
The current public release lines are documented in
book/src/operations/release-contract.md and
book/src/operations/versioning.md. Older releases may still be
investigated, but maintainers may ask you to reproduce the issue on a current
build before triage.
After a report is validated, maintainers will:
- scope the affected surfaces
- prepare and verify a fix
- coordinate release timing through the existing release workflows
- publish disclosure details once users have a remediation path
For parser bugs, feature requests, documentation issues, and other non-security
reports, use the standard GitHub issue templates in .github/ISSUE_TEMPLATE/.