We take security bugs seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.
Please do not report suspected vulnerabilities in public issues, discussions, pull requests, or other public channels.
- Creating a Security Advisory is the best way to report a vulnerability. [Report a vulnerability](TODO: Link to https://github.com/natrontech/REPO/security/advisories/new)
- If private vulnerability reporting is unavailable, email security@natron.io.
When a security issue is confirmed, we will:
- Develop and test a fix
- Assign a CVE identifier if appropriate
- Release a patched version
- Publish a security advisory via [GitHub Security Advisories](TODO: Link to https://github.com/natrontech/REPO/security/advisories)