AcornOps is under active development. Security reports are accepted for the current default branch and any active development branches maintained by the AcornOps team.
Please do not open a public GitHub issue for suspected security vulnerabilities.
Report security issues through the AcornOps Discord:
Include enough detail for maintainers to understand and reproduce the issue, such as affected repositories, components, versions or commit SHAs, impact, steps to reproduce, and any relevant logs or screenshots. Do not include live secrets, tokens, private keys, or customer data in the report.
Give the AcornOps maintainers time to acknowledge, investigate, and remediate a valid vulnerability before public disclosure. Maintainers may follow up through Discord for reproduction details, mitigation guidance, and coordinated disclosure timing.