Use GitHub's private vulnerability reporting on the affected repository (Security tab → Report a vulnerability) — enabled on all PSD401 repos. You'll get an acknowledgment within 3 business days.
No repo in this organization should contain student data; if you believe you've found any, report it privately and immediately — do not open a public issue.
All non-archived repositories in the PSD401 organization. Archived repos are frozen historical code and are not maintained.
Test against live district systems or student-facing services without written authorization from Technology Services.