Security Policy

Please report vulnerabilities by using the GitHub Vulnerability Reporting Feature which is documented here or privately on security@bugsink.com

Disclosure posture

We follow responsible disclosure. Please do not publish details before we’ve had a reasonable chance to investigate and ship a fix.

When you report an issue, include reproduction details where possible. We will acknowledge the report and follow up directly.

Disclosures / write-ups

The most up-to-date list of security advisories is available on GitHub.