- Use GitHub private vulnerability reporting for security disclosures.
- Expect acknowledgement within 72 hours.
In scope:
- auth bypass
- approval gate bypass
- credential leakage
Out of scope:
- issues that require physical access to an operator machine without any platform vulnerability
- problems caused only by placeholder credentials in
env.example
- Report privately first.
- Do not publish exploit details until the issue is acknowledged and a fix window is agreed.
- Include reproduction steps, affected files or endpoints, and deployment assumptions.
This project is distributed under AGPL-3.0-or-later without warranty. That license posture does not reduce the importance of promptly reporting and fixing real security issues.