Please report security vulnerabilities privately — do not open a public GitHub issue for a security bug.
- Email info@penca.io, or
- Use GitHub's private vulnerability reporting: the repository's Security tab → Report a vulnerability.
Include enough detail to reproduce the issue (affected component, version or commit, and reproduction steps). We acknowledge reports on a best-effort basis; there is no formal SLA at this stage.
Penca is pre-1.0 and moving quickly. Only the latest main is supported —
fixes land there, and we do not back-port to older commits or tags.