Reporting a vulnerability
A dedicated private reporting channel has not yet been configured. Do not publish vulnerability details in public issues. If the website repository offers private vulnerability reporting, use its Security tab. Otherwise, request a private contact through an available project channel without disclosing exploit details.
Include the affected URL, a concise description, minimal reproduction steps, the potential impact, and any suggested fix. Redact credentials and personal information.
Keep testing bounded
Avoid accessing other people’s information, modifying data, degrading availability, or testing third-party services. Stop if a test exposes sensitive information and report only the minimum necessary to describe the issue.
Review and coordination
Once a private channel is established, maintainers can assess the report, coordinate a fix, and agree on disclosure. No response-time guarantee or bounty program is offered. Reports about sibling projects should follow those projects’ own security policies.