If you believe you have found a security vulnerability, please do not open a public GitHub issue.
- Use GitHub's "Report a vulnerability" flow (Security tab) if it is available for this repository.
- If that flow is not available, create a draft security advisory (Security tab → Advisories → New draft advisory), and include the details below.
- If neither option is available, contact the maintainer privately via the email listed on the maintainer’s GitHub profile.
- A clear description of the issue and potential impact
- Reproduction steps (exact commands / inputs)
- Any suggested mitigations or patches, if you have them
- Version/commit information (branch, tag, or commit SHA), if known
- We will acknowledge receipt and triage the report.
- We prioritize issues that could lead to data exposure, unauthorized access, or integrity loss.
- We aim to acknowledge reports within 7 days and provide a status update within 30 days.
In scope
- Vulnerabilities in this repository’s code, CI workflows, and related configuration
Out of scope
- Third-party services
- Social engineering
- Denial-of-service testing or disruptive scanning
- Testing against systems you do not own or have explicit permission to test
We support good-faith security research. Please avoid privacy violations, destructive testing, and service disruption. If you act in good faith and follow this policy, we will not pursue legal action against you.
This project is currently early-stage; security posture will improve as deployment guidance and authentication layers mature.