Do not disclose vulnerabilities, credentials, tokens, account information or exploit details in a public GitHub issue.
Use GitHub's private security-advisory reporting feature for this repository if enabled. If it is unavailable, use the private contact method published on the Citation Gap website.
Include:
- A clear description of the issue
- Affected URL or component
- Reproduction steps using non-sensitive test data
- Potential impact
- Suggested remediation, if known
Allow reasonable time for investigation before public disclosure.
This repository contains public documentation, not the production implementation. Reports about the hosted endpoint, authentication flow or hosted reports should still be submitted privately.
Never commit API keys, OAuth credentials, cookies, tokens, customer data or Cloudflare secrets to this repository.