The latest state of main is the supported version.
Please report vulnerabilities privately via GitHub's security advisories ("Report a vulnerability" on the repo's Security tab). Do not open a public issue for security problems.
You can expect an initial response within a week. There is no bug bounty.
- The server is designed to run behind your own reverse proxy / TLS termination; it speaks plain HTTP itself.
- Anything reachable with the bootstrap
PRINTAPI_TOKENis root-equivalent for the print system — treat that token like a password.