Please do not open a public issue for security problems.
Report vulnerabilities privately through GitHub's private vulnerability reporting, or e-mail support@keydown.io with "Security" in the subject.
Please include:
- a description of the issue and its impact,
- steps to reproduce or a proof of concept,
- any suggested fix, if you have one.
We will acknowledge your report, keep you updated while we investigate, and credit you in the fix if you wish.
In scope: this repository and the service running at keydown.io.
Out of scope: denial-of-service and volumetric attacks, social engineering, and findings that require a compromised device or browser.
Please test only against your own account and never access or modify other users' data.
Only the latest version on main (what is deployed to keydown.io) receives security fixes.