Thanks for helping keep this project and its users safe.
Security fixes are applied to the latest version — the newest commit on main for apps, the latest published version for packages. Older commits and versions are not patched.
Please do not open a public GitHub issue for security vulnerabilities.
Use the repository's Security tab → Report a vulnerability. This opens a private channel between you and the maintainer — nothing you submit is publicly visible until we publish the advisory together after a fix ships.
Please include:
- A clear description of the issue and its impact
- Steps to reproduce (including the version, commit, or deployed URL you tested against)
- Any proof-of-concept code or logs, if relevant
- Whether you'd like to be credited in the fix announcement
- Acknowledgment within 72 hours of your report reaching me.
- Initial triage within 7 days — I'll let you know whether the report is accepted, declined, or needs more detail.
- Fix timeline depends on severity. Critical issues (data leakage, auth bypass, RCE) are prioritised immediately; lower-severity issues may take longer.
- Credit. Reporters of accepted vulnerabilities get credit in the release notes and advisory, unless you prefer to remain anonymous.
- Coordinated disclosure. Please give me a reasonable window to ship a fix before publishing details. 90 days is a common baseline; I'll aim faster for anything serious.
- Vulnerabilities in third-party services a project depends on — please report those directly to the respective vendors
- Missing best-practice HTTP headers with no concrete impact
- Findings from automated scanners without a reproducible exploit
A repository with its own SECURITY.md overrides this default and may define a more specific scope.