Menu

Security

Report a security issue.

Send the smallest reproducible case and remove credentials, serial numbers, hostnames, network addresses, and user data.

Private reporting route

  1. Sign in to GitHub and open the repository Security area.
  2. Use private reporting if it is available.
  3. Otherwise, open a short public issue asking for a private contact route. Keep exploit details private.

Start from the repository Security area. No security email or response time is currently published.

Keep secrets out of public issues.

Remove passwords, API keys, session data, raw serial numbers, hostnames, network addresses, filesystem paths, and identifiable production data.

This website is static

Pages load local CSS and JavaScript only. There are no forms or account sessions to test.

Safe testing

Test only systems and data you own or have permission to test. Avoid destructive operations, disruption, social engineering, persistence, and other people’s data.