If you discover a security vulnerability in CROW, please report it responsibly:
- Do not open a public GitHub issue.
- Email buzzcrow@126.com with a description of the vulnerability and reproduction steps.
- You will receive an acknowledgment within 48 hours.
CROW is currently a pre-production project. Security fixes will be prioritized but may not have defined SLAs.
Once a fix is released, we will publish a GitHub Security Advisory crediting the reporter (unless they prefer to remain anonymous).