If you believe you have discovered a security issue within a d9 product or service, please open a new private security vulnerability report. Do not open a public issue for security problems.
d9 values the members of the independent security research community who find security vulnerabilities and work with our team so that proper fixes can be issued to users. Our policy is to credit all researchers in the fix's release notes. In order to receive credit, security researchers must follow responsible disclosure practices, including:
- They do not publish the vulnerability prior to the d9 team releasing a fix for it
- They do not divulge exact details of the issue, for example, through exploits or proof-of-concepts