Security fixes are made against the latest published release. Older pre-1.0 releases may not receive separate security updates, so users should upgrade to the newest release before reporting a problem.
Do not disclose a suspected vulnerability in a public issue, discussion, or pull request.
Use GitHub's private vulnerability reporting form:
https://github.com/moonbitlang/moonback/security/advisories/new
Include the affected version, impact, reproduction steps or proof of concept, and any suggested mitigation. Remove credentials and unrelated personal data from the report. If private vulnerability reporting is temporarily unavailable, contact a repository maintainer privately before disclosing the issue.
The maintainers will coordinate disclosure after a fix or mitigation is available. Please allow a reasonable amount of time for investigation and affected users to update.