Responsible security reporting
Report privately
Do not publish vulnerabilities, personal data, credentials, or operational secrets in public issues. Once the official GitHub repository is configured, use its private vulnerability reporting feature. Until a private channel is published, contact an appointed maintainer privately; no public disclosure inbox is claimed by this preview.
What to include
Describe the affected version, reproduction steps, likely impact, and a safe proof of concept. Do not access other people’s data or test destructively. Agree a disclosure timeline with the maintainer.
Baseline controls
All exposed database tables use row-level security. Protected actions verify the current user on the server. Validate input, restrict external URLs, prevent cross-origin mutations, rate-limit submissions and claims, and audit privileged changes.