Security reports are accepted for the latest release published from this repository.
Use GitHub's Private vulnerability reporting feature for anything sensitive. Do not place exploit details, credentials, personal data, or private repository contents in a public issue.
For non-sensitive bugs, open a normal GitHub issue with reproduction steps, expected behavior, actual behavior, environment details, and sanitized evidence.
- These projects are local releases, not production services.
- Keep all tests on data and systems you own or are authorized to inspect.
- Do not upload live credentials, customer data, or private repositories to public issues.
- ReadTheRoom and MAYA Sentinel run locally by default; do not expose their loopback development servers directly to the internet.
We will acknowledge a valid private report as quickly as practical, investigate it, and publish a fix or mitigation when appropriate.