Security Policy
Our security policy, security advisories, and vulnerability tracking takes place through our GitHub repositories' Security section.
Read this first
We accept vulnerability reports as per the Security Policy of each project. We are a tiny, single-person company; we don't have a bug bounty program, nor can we afford one.
Please make sure that you submit the advisory in the correct project's repository. It makes it much easier to track what is going on.
Before submitting a vulnerability report, please make sure it's reproducible under the latest code in the main branch and that the root cause is our code, not the operating system, or the site or third party service you are connecting to.
A proof of concept is highly appreciated, but not necessary. Likewise for a proposed fix.
Thank you for helping keep everyone safe! ❤️