generated: '2026-08-30' method: searched source: https://raw.githubusercontent.com/facebookresearch/.github/main/SECURITY.md provider: AI Habitat providerId: ai-habitat description: >- Vulnerability disclosure policy covering the AI Habitat repositories. AI Habitat serves no /.well-known/security.txt (probed 2026-08-30, 404 on aihabitat.org — see well-known/ai-habitat-well-known.yml). The policy that actually governs habitat-sim and habitat-lab is the facebookresearch organization SECURITY.md, which GitHub renders on every repository in the org, and which routes reports into the Meta Bug Bounty program. policy: published: true url: https://github.com/facebookresearch/habitat-lab/security/policy raw_url: https://raw.githubusercontent.com/facebookresearch/.github/main/SECURITY.md http_status: 200 probed: '2026-08-30' scope: >- Organization-wide: the file lives in facebookresearch/.github and therefore applies to facebookresearch/habitat-sim, facebookresearch/habitat-lab and facebookresearch/partnr-planner. statement: >- "Please do not open GitHub issues or pull requests - this makes the problem immediately visible to everyone, including malicious actors. Security issues in this open source project can be safely reported via the Meta Bug Bounty program: https://www.facebook.com/whitehat. Meta's security team will triage your report and determine whether or not is it eligible for a bounty under our program." bug_bounty: program: Meta Bug Bounty url: https://www.facebook.com/whitehat platform: first-party paid: true note: >- Bounty eligibility is decided by Meta's security team on triage. The whitehat URL was not independently probed successfully from this run (returned 400 to our client, a bot/edge policy rather than a dead page); it is recorded here as published by the provider in SECURITY.md. security_txt: published: false probed_path: https://aihabitat.org/.well-known/security.txt http_status: 404 disclosure_channel: preferred: Meta Bug Bounty submission prohibited: [GitHub issue, GitHub pull request] coordinated_disclosure: true caveat: >- Read this alongside lifecycle/ai-habitat-lifecycle.yml: both READMEs state the project receives no official active development or maintenance beyond v0.3.4, so a reported vulnerability has a documented intake route but no stated maintenance commitment behind it.