Report a vulnerability in the relay to security@perfloop.ai. That is the address Perfloop publishes for security questions and reviews; it reaches the people who maintain this repository. Include the commit or image digest you looked at, how to reproduce, and what you believe the impact is. Do not open a public issue for a vulnerability.
Supported: the main branch and the latest published image (docs/image.md).
A fix lands on main and is published as a new image; you choose when to roll
it, as with every relay change. This document makes no commitment beyond the
address: no response time, embargo, or reward program is published here.