Use GitHub private vulnerability reporting for suspected vulnerabilities.
If GitHub private reporting is unavailable, email nahuel@galinum.com.
Include:
- The affected commit or version.
- Reproduction steps or a minimal proof.
- The expected and actual security boundary.
- Any known workaround.
Do not include secrets, customer data, or an exploit in a public issue.
Galinum has not published a stable release. Security fixes currently target the latest main commit. This policy will list supported release lines before the first public release.
This repository does not contain Galinum Cloud billing, tenant provisioning, managed credentials, or operations. Report a boundary violation as a security issue even when no credential is present.