| Branch | Supported |
|---|---|
main |
Yes |
| Other branches | Best effort only |
Do not open a public issue for security vulnerabilities.
Report privately to @Mutx163 or via GitHub Security Advisories.
Include:
- Affected adapter or script path under
resources/ - Steps to reproduce
- Impact (credential leak, arbitrary code execution in WebView import, etc.)
- Never commit real usernames, passwords, cookies, tokens, or raw packet captures
- Test credentials belong in local-only files ignored by
.gitignore - Scripts must not exfiltrate user data to third-party endpoints
- Initial acknowledgment: within 7 days
- Critical issues (malicious adapter code): prioritized
- Bugs in individual school adapters that only affect import UX — use normal Issues/PRs
- Problems in the main app (mikcb) — report there instead