Security fixes are applied to the latest code on the default branch. Older releases and downstream forks are not guaranteed to receive fixes.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting and include:
- The affected component and version or commit.
- Reproduction steps or a proof of concept.
- The likely impact and any known mitigations.
- Whether the issue involves authentication, personal data, MLS data, or credentials.
You should receive an acknowledgment within five business days. We will investigate, coordinate a fix and disclosure timeline, and credit reporters who want attribution. Please avoid accessing data that is not yours, disrupting services, or publicly disclosing the issue before a fix is available.
Frontstead deployments are independently operated. If a vulnerability affects only a specific deployment or fork, contact that operator directly.