If you discover a security vulnerability in tofig, please report it privately. Do not open a public issue or pull request, as that may put users at risk before a fix is available.
Please report vulnerabilities via one of:
- GitHub's private vulnerability reporting (preferred), or
- Email to tiago.moraes@aca.so
When reporting, please include where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- Affected version(s) and environment
We will acknowledge your report as soon as we can, keep you informed of progress, and credit you once a fix is released (unless you prefer to remain anonymous).
This project is in early development. Until a stable 1.0 release is published,
only the latest version on the main branch is supported with security fixes.