Thanks for helping keep this project and the people using it safe 💛
Our version history is liniar, and we use semantic versioning. Only the latest release gets patched, so check you're on it before reporting anything.
Important
Please don't report anything publicly (issues, PRs, discussions) without giving us at least 30 days to respond and handle it.
Acceptible channels:
- GitHub (preferred) - open an advisory from the Security tab
- Email - security@peng.ly (PGP:
A8431F9F332FB0CD)
Include the type of issue, the affected version and file paths, steps to reproduce, a PoC if you've got one, and what an attacker could actually achieve with it.
Keep it short, and don't over-state the impact - it's not helpful. Using AI is fine, just say that you have.
I'll try to acknowledge and triage within 48 hours. If it's valid, I'll get a fix out within 2 weeks and publish the advisory, and I'll keep you updated throughout.
Coordinated, so give us a fair chance to ship a fix before going public. Happy to credit you in the advisory and release notes, or leave you out of it - your call.
Report in good faith, stick to this policy, and steer clear of privacy violations, data destruction and service disruption, and I won't pursue or support legal action against you.