Security
Security Acknowledgements
Current acknowledgements
No public acknowledgements are recorded yet. An empty list does not mean that the service has received no reports. Reporters may remain anonymous, decline recognition, or work under a coordinated disclosure embargo.
Recognition policy
After remediation and coordinated disclosure, the maintainers may list a reporter's chosen public name and link only with the reporter's explicit consent. The acknowledgement will identify the affected release or deployment and the public advisory when one exists. It will never disclose private contact details or embargoed technical material.
Report privately
Follow the instructions in the security policy or the canonical security.txt. Do not open a public issue for a suspected vulnerability.