Security

Security Acknowledgements

Current acknowledgements

No public acknowledgements are recorded yet. An empty list does not mean that the service has received no reports. Reporters may remain anonymous, decline recognition, or work under a coordinated disclosure embargo.

Recognition policy

After remediation and coordinated disclosure, the maintainers may list a reporter's chosen public name and link only with the reporter's explicit consent. The acknowledgement will identify the affected release or deployment and the public advisory when one exists. It will never disclose private contact details or embargoed technical material.

Report privately

Follow the instructions in the security policy or the canonical security.txt. Do not open a public issue for a suspected vulnerability.