Only the latest release on the Releases page receives security fixes. Older versions are not patched; update to the latest release before reporting.
Report vulnerabilities privately through GitHub private vulnerability reporting. Do not open a public issue or pull request for security problems.
Include the affected version, steps to reproduce, and the impact you observed. You will receive an acknowledgement within 7 days.
Runly follows a 90-day coordinated disclosure window. A fix is prepared and released within 90 days of the report where possible, after which the advisory is published. If a fix is available sooner, the advisory is published together with the release that contains it.