Please do not open a public issue for security problems.
- Preferred: GitHub private vulnerability reporting — Security → Report a vulnerability on this repo.
- Alternative: email vlad@sterngold.nl with a description and reproduction steps.
You will get a response within 7 days. Confirmed issues are fixed on main; there is no bounty program.
Only the latest main (and the latest tagged release, where releases exist) receives security fixes.
This policy ships with the template: repos generated from anders-repo-template inherit this file and the same reporting path unless they override it.