Ferry is pre-alpha and has no supported production release. Security reports are still useful, especially when they concern the planned webhook signature contract, secret handling, PostgreSQL privileges, operator APIs, or dependency and build integrity.
Do not include real credentials, personal information, production data, private infrastructure details, or sensitive payloads in a public issue, discussion, pull request, test, or example.
Use GitHub private vulnerability reporting when it is available for this repository. If no private reporting channel is visible, open a minimal public issue asking maintainers to establish a private channel. Do not include vulnerability details or sensitive evidence in that issue.
Reports and reproductions should use synthetic data and the smallest safe proof of concept. Replace secrets and private endpoints with explicit placeholders.
If a real credential or private key is exposed, revoke or rotate it immediately. Removing it from the latest commit is not sufficient because published Git history, forks, caches, and logs may retain it. Coordinate any history rewrite separately after rotation.