If you have found a security issue or concern with Kroki, please report it by creating a private security advisory on GitHub.
This allows us to discuss and fix the issue privately before any public disclosure. Please do not open a public GitHub issue or discuss the vulnerability in public channels.
We will do everything we can to communicate in a timely manner and address your concerns, but realize that we do have day jobs and this is an open source project, so have a little patience if you don't hear back from us immediately.