Please report suspected vulnerabilities privately through GitHub Security Advisories:
https://github.com/arkadyb/corpulse/security/advisories/new
Do not open a public issue for security-sensitive reports.
Include:
- Affected versions or commit SHAs.
- A minimal reproduction or proof of concept.
- Expected impact and any known mitigations.
- Whether the report includes private data or third-party credentials.
Until the project reaches a stable release, security fixes are made on the default branch and released in the next package version as needed.
Maintainers should acknowledge reports within seven days, triage privately, and publish a GitHub Security Advisory if users need to take action.