We take the security of our software and our clients' data seriously. Thanks for helping keep GattyWorks and our users safe.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, email us at hello@gattyworks.com with a subject line that starts with "Security". If a repository has GitHub private vulnerability reporting enabled, you may use that instead.
Please include as much of the following as you can:
- The type of issue, for example injection, authentication bypass, or data exposure.
- The repository and the affected file paths or endpoints.
- The branch, tag, or commit where you observed it.
- Step by step instructions to reproduce.
- Proof of concept or exploit code, if you have it.
- The impact, and how an attacker might use it.
- We acknowledge your report within 24 hours.
- We confirm the issue and keep you updated on the fix.
- We agree a disclosure timeline with you, and credit you if you wish.
Please act in good faith, avoid privacy violations and service disruption, and give us reasonable time to respond before any public disclosure.