Report vulnerabilities privately through GitHub Security Advisories at https://github.com/Quad4-Software/quickchat/security/advisories/new or by email to security@quad4.io.
Do not open public issues for security reports. We acknowledge reports within a few days and aim to ship fixes promptly.
quickchat is a self-hosted service. Reports are in scope for the application code and its published container image, not for instances operated by third parties.
Only the latest release and the master branch receive fixes.