During the release-candidate phase, only the newest published 0.1.x release
receives security fixes.
Use the repository host's private vulnerability-reporting feature. If it is not available, use the private contact method published at https://www.immution.com/.
Do not open a public issue containing exploit details, real IP state, access logs, credentials or customer hostnames.
Include:
- affected version and installation method;
- clear reproduction steps using documentation-only IP ranges;
- likely impact and prerequisites;
- a proposed fix, if available.
An initial acknowledgement is targeted within three business days. This is a maintainer response target, not a commercial SLA.