Security reports are welcome for the current main branch and for deployed instances based on the current repository state.
Do not open a public GitHub issue for a suspected vulnerability.
Instead, report it privately to the repository owner with:
- A short description of the issue
- Impact and affected surface
- Reproduction steps or proof of concept
- Any suggested mitigation if you already have one
If a private reporting channel is added later, this document should be updated to point to it explicitly.
- Whether the issue affects the web app, CLI, API, or deployment configuration
- Required preconditions
- Whether authentication is required
- Any relevant logs, screenshots, or request examples
Reports will be triaged as time permits. Valid reports should receive acknowledgment, impact assessment, and either a fix or a documented mitigation path.