If you discover a security issue, do not open a public issue with exploit details.
Instead, report it privately to the maintainers with:
- a clear description of the vulnerability
- reproduction steps or proof of concept
- impact assessment
- suggested mitigation (if available)
- Initial triage target: within 3 business days.
- Confirmed vulnerabilities should be patched as quickly as possible.
- Public disclosure should happen only after a fix is available.
- Never commit secrets (
.env*, tokens, API keys, private credentials). - Validate all external inputs before use.
- Avoid logging sensitive user data.
- Keep dependencies updated and remove unused packages.
- Re-check API base URLs before environment changes.