This policy covers the MIT reference servers in this repository (the collaboration server and the AI proxy) and their third-party dependencies. Neither server installs a Domternal Pro package. If you copied this repository as a template for your own deployment, replace this file with your deployment's own reporting channel: Domternal cannot fix or even see your fork.
Please do not report security vulnerabilities through the public issue tracker. A public security issue is an exploit announcement for every deployment that has not patched yet.
Email security@domternal.dev.
Please include:
- A description of the vulnerability and its impact
- Steps to reproduce, ideally with a minimal example
- Whether it affects a server in this repository or an installed package, and the release tag or full Git commit SHA
Security reports are read with priority. Please allow time for a fix to reach deployments before any public disclosure.
Defects that are not security issues are welcome on the issue tracker.