Security

Report security issues responsibly.

Send a concise description of the affected public asset, the observed behavior, reproduction conditions, and potential impact.

  • Do not include passwords, tokens, private keys, customer data, or unrelated confidential material.
  • Do not perform denial-of-service testing, destructive testing, persistence, social engineering, or access beyond what is necessary to describe the issue.
  • Do not assume a bug bounty, payment, response deadline, or remediation deadline.
  • Preserve enough technical detail for review while minimizing sensitive data.