If you discover a security vulnerability, please report it by email to security@ivanbeltrame.com.
When reporting a vulnerability, please provide the following information:
- A clear description of the issue and its potential impact.
- Steps to reproduce the vulnerability (e.g., code snippets, proof of concept, affected endpoints).
- Any known mitigations or workarounds.
- The severity or risk level as you assess it.
We ask that you:
- Do not publicly disclose the vulnerability before it has been addressed.
- Allow a reasonable amount of time (typically 30 days) for remediation.
- Avoid testing on production systems without prior consent.
We commit to acknowledging your report as soon as possible and providing regular updates thereafter.
Thank you for helping keep the project and its users safe.