Do not report security vulnerabilities in public GitHub Issues.
Use GitHub's private vulnerability reporting to provide a description, affected versions, reproduction steps, and any suggested mitigation. Do not include live AWS credentials or session tokens.
Reports are handled on a best-effort basis. Please allow time for triage before disclosing the issue publicly.
Security reports are in scope when they affect Quorra's handling of AWS folder access, Keychain-backed credentials, IAM Identity Center authentication, local IMDS endpoints, signing, or release artifacts.