Do not post security vulnerabilities or sensitive details in a public issue. Public issues are for ordinary bugs, installation and compatibility problems that do not expose confidential information or exploitation steps.
To report privately:
- Use GitHub Private Vulnerability Reporting (the repository's Security tab → Report a vulnerability) when it is available for this repository. Only the maintainer and the people added to the advisory can see the report.
- If it is not available, or you prefer email, write to security@sggaray.com.
Please include:
- The affected version or commit.
- The operating system and desktop environment when relevant.
- The minimum steps required to reproduce the issue.
- The observed security impact.
- Sanitized logs or screenshots when useful.
- A proof of concept using synthetic data where possible.
Do not include credentials, tokens, private documents, personal data, or other sensitive information in the report.
There is no bug bounty and no committed response time. The maintainer will try to acknowledge the report and coordinate disclosure. This policy does not imply that GuionAR has been audited or certified.