Services operated by the U.S. General Services Administration (GSA) are covered by the GSA Vulnerability Disclosure Policy. See the policy page for details including:
- GSA's coordinated disclosure policy.
- Information on how you may conduct security research on GSA developed software and systems.
- Important legal and policy guidance.
Security issues should be reported via GitHub private vulnerability reporting (requires a GitHub account) or by sending an email to dap@gsa.gov.
Security issues may also be reported to the GSA Vulnerability Disclosure Program, following instructions in the policy linked above. However, we ask that you report directly to us as well, to ensure that the issue will be reviewed quickly.
Please note that only the most recent major version of the DAP code is supported with security updates.
Version | Supported |
---|---|
8.x | ✅ |
< 8.0 | ❌ |
When using this code or reporting vulnerabilities, please only use supported versions.