If you discover a security vulnerability in GT Office, please report it responsibly:
- Email: opensource@gtoffice.dev
- Do not file a public GitHub issue for security vulnerabilities.
We ask that you:
- Report vulnerabilities privately via the email above.
- Provide enough detail to reproduce the issue.
- Allow us a reasonable time to respond and fix before any public disclosure.
- Acknowledgment: Within 48 hours
- Initial assessment: Within 5 business days
- Fix & disclosure: We will coordinate a timeline with you after assessment
Security updates are applied to the latest release. We do not backport fixes to older versions.
We appreciate responsible disclosure and will credit researchers who report vulnerabilities (unless you prefer to remain anonymous).