Responsible disclosure
Security
Security reports are reviewed in good faith. Please use the private channel below so users are not put at risk.
Report privately
Submit suspected vulnerabilities through GitHub private vulnerability reporting ↗. Include reproducible steps, affected routes, impact, and a safe proof of concept when possible.
Safe research expectations
Do not access, alter, retain, or disclose another user's data. Do not disrupt production, degrade availability, send spam, use social engineering, or test third-party providers without permission. Use the minimum access needed to demonstrate the issue and stop if sensitive data appears.
What happens next
Reports will be reviewed and may receive requests for clarification. Response and remediation timing depends on severity and reproducibility. Please allow a reasonable remediation period before disclosure. This page does not create a bug bounty or authorize activity prohibited by law.