Security
Report suspected vulnerabilities privately and protect sensitive information.
Report privately
Do not open public issues containing vulnerability reproduction details, credentials, tokens, cookies, session material, webhook secrets, private provider payloads, or personal reading data.
Use the affected repository's private GitHub security-advisory channel when it is available. The channel directory below reports whether a public reporting destination has been approved. If it is unavailable, do not substitute a public issue; wait for a documented private channel. No security email address is currently published.
What to include
Describe the affected product and version, impact, reproduction conditions, and a proposed mitigation when known. Use a minimal example and redact secrets and personal data. Do not access other people's accounts or data to demonstrate a problem.
Maintainers may request clarification and coordinate a fix before public disclosure. No response deadline or supported-version guarantee is currently published. All products remain In development; use release notes for information accompanying approved releases.
General help
Ordinary bugs and troubleshooting belong in support, using sanitized reports. The website has no report-upload form and does not collect vulnerability reports itself. Review privacy before following external reporting links.
GitHub channels
Public reporting destinations have not yet been confirmed. No information is submitted by this website.
Private security reporting
Use the affected repository’s private GitHub security-advisory channel. Do not post vulnerabilities in public issues.
Public channel unavailable.