Sanakota is in active alpha. Please treat authentication, account management, and generated dictionary fallback paths as security-sensitive areas.
Please do not open a public issue with exploit details.
Use GitHub's private vulnerability reporting for this repository when available. If private reporting is unavailable, contact the repository owner through GitHub and share only a short description until a private channel is established.
Helpful details include:
- Affected endpoint, package, or workflow
- Reproduction steps
- Expected impact
- Relevant logs with secrets removed
Only the main branch is currently supported.
Never commit .env files, API keys, database dumps with user data, or provider responses containing private text. The checked-in .env.example files are development defaults only.