Please do not open a public issue for security vulnerabilities.
Report privately via:
- Email: contact@markaronov.com — mark the subject "Security Disclosure"
- GitHub: use Private Security Advisory
Include:
- Description of the vulnerable component and potential impact
- Steps to reproduce with a minimal proof of concept (if possible)
- Any suggested patches or mitigations
| Step | Target |
|---|---|
| Acknowledgement | 48 hours |
| Initial assessment | 5 business days |
| Fix / coordinated disclosure | Depends on severity |
Security fixes are applied to the latest release only. Update before reporting.