Please report suspected security vulnerabilities privately through GitHub's private vulnerability reporting.
Do not open a public issue or discuss the vulnerability in a public channel before it has been addressed.
Alternatively, report security vulnerabilities by email to m0wer [at] sgn [dot] space, encrypted with the PGP key below.
Fingerprint: 1C53A412D11EF3051704419C44912E1E03005B31
The full public key is available in the repository at
signatures/pubkeys/1C53A412D11EF3051704419C44912E1E03005B31.asc.
A useful report covers:
- a description of the vulnerability and its impact
- steps to reproduce or a proof-of-concept
- affected versions or components
- any suggested mitigations
- Acknowledgment within a few days.
- Coordinated disclosure: a fix will be prepared before public disclosure.
- You will be credited in the release notes unless you prefer otherwise.
We may offer bounties paid in Bitcoin for critical vulnerabilities, but cannot make firm commitments due to budget constraints. Severity and impact determine eligibility on a case-by-case basis.
