We take the security of this project very seriously. If you discover a security vulnerability or issue, please do not open a public issue on GitHub, as it may expose the vulnerability to the public before it is resolved.
Instead, please report security vulnerabilities privately by contacting us at:
- Submit a security report via GitHub Security Advisories
Please include as much detail as possible, including steps to reproduce, impact assessment, and any relevant code or configuration.
- We will acknowledge receipt of the security report within 48 hours.
- We aim to investigate and address security issues promptly.
- If applicable, we will release patches or updates and notify affected users.
- We will keep reporting parties informed about the progress until the issue is resolved.
Please specify which versions of the project are affected by the reported vulnerability.
- Do not commit any sensitive information (API keys, secrets) to the repository.
- Use environment variables to manage secrets securely.
- Keep dependencies up-to-date to avoid security risks in third-party libraries.
- Follow best practices for authentication and authorization.
For more information on responsible disclosure, visit GitHub's Security Overview.
Thank you for helping keep this project secure!