I take security seriously and will actively work to resolve security issues.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, please send an email to [email protected]. I ask that you give me sufficient time to investigate and address the vulnerability before disclosing it publicly.
Please include the following details in your report:
- A description of the vulnerability
- Steps to reproduce the vulnerability
- Your assessment of the potential impact
- Any possible mitigations
While I do my best to secure my project, users are encouraged to implement their own security best practices, such as:
- Regularly updating to the latest version of the project
- Securing access to hosted instances of the project
- Monitoring systems for unusual activity
For any other questions or concerns, please contact me at [email protected].