Skip to content

Latest commit

 

History

History
31 lines (21 loc) · 933 Bytes

File metadata and controls

31 lines (21 loc) · 933 Bytes

Security Policy

Supported Versions

Security fixes are applied to the latest main branch.

Reporting a Vulnerability

Please do not report security vulnerabilities in public issues.

Preferred channels:

  • GitHub Security Advisories (private report in this repository).
  • If unavailable, open a minimal private contact request and we will provide a secure channel.

When reporting, include:

  • Affected component and endpoint/file.
  • Reproduction steps.
  • Impact and severity estimate.
  • Suggested mitigation (if available).

Scope Notes

  • This project is defensive by design.
  • Vulnerability reports that require unauthorized targeting are out of scope.
  • Reports should focus on misuse risk, data exposure, auth bypass, RCE, SSRF, path traversal, and unsafe defaults.

Response Goals

  • Initial triage: within 5 business days.
  • Status updates: as fixes progress.
  • Coordinated disclosure after patch availability.