Do not report security vulnerabilities in a public issue, pull request, or community chat.
Email oss@nomyr.io with:
- a concise description and potential impact;
- the affected version, commit, component, or contract;
- safe reproduction steps or a proof of concept;
- a secure way to contact you.
Do not include live credentials, personal data, customer data, or private infrastructure details. The maintainers will acknowledge the report, coordinate validation, and agree on disclosure timing with the reporter.
The local demo is synthetic and loopback-only. Do not expose it publicly or connect it to production credentials while reporting an issue.