Please do not report suspected security vulnerabilities in public GitHub issues or Discussions.
If GitHub Private Vulnerability Reporting is enabled for the affected repository, use it.
Otherwise, contact the EpikodeLabs maintainers privately and include:
- the affected project and version or commit;
- a description of the vulnerability;
- reproduction steps or proof of concept when available;
- the expected security impact;
- any known mitigations.
Please avoid accessing, modifying, or exposing data that is not yours while investigating a vulnerability.
We will try to:
- acknowledge a valid report;
- reproduce and assess the issue;
- determine affected versions;
- prepare a fix or mitigation;
- coordinate disclosure when appropriate.
Response times may vary because EpikodeLabs is a small open-source organization.
Unless a repository documents a different policy, security fixes are generally targeted at the latest actively maintained release line.
Older releases may not receive patches.
Please allow maintainers a reasonable opportunity to investigate and fix a vulnerability before publishing details that could put users at risk.
We appreciate responsible security research and clear reports.