If you believe you have found a security vulnerability in this repository, please report it privately.
- Do not report security vulnerabilities through public GitHub issues.
- Email the project maintainer at
bketelsen@gmail.com. Use a subject such as
[snosi security] Brief description. - If this repository's Security tab displays a Report a vulnerability button, you may use that private form instead.
The New draft security advisory page is a maintainer workflow and is not a fallback reporting channel for people without repository write access.
- Include the affected version or commit, impact, and complete reproduction steps when possible.
- Do not send credentials, private signing material, or executables.
- You may include scripts you wrote, but do not send scripts that download and run binaries.
- We prioritize reports that demonstrate realistic impact.
- We prefer communications in English.
- We do not offer financial rewards. We are happy to acknowledge your research publicly when possible.