Report suspected vulnerabilities privately to creator@localzet.com. Include the repository, affected commit/version, impact, minimal reproduction and suggested fix when available. Do not post credentials, real customer data or exploitable details in public issues. We do not promise a response SLA or a bounty.
Use the latest reviewed revision and inspect README for experimental or unsupported features; a passing CI run is not a security certification. Maintained release lines must be explicitly documented before relying on backports. Until then, fixes target the current development line on a best-effort basis.
Never transmit live secrets by email. Redact evidence and arrange a suitable private channel with the maintainer if sensitive material is necessary. Coordinate public disclosure after a fix or an agreed disclosure date. Preserve attribution when reporting or adapting upstream fixes.
Maintainer: Ivan Zorin (localzet). Author information: .github/AUTHORS.md.