This repository is actively maintained on the main branch.
Please do not open public issues for sensitive vulnerabilities.
Report privately by email to the repository owner with:
- affected component/path
- impact summary
- reproduction steps
- suggested mitigation (if available)
- initial triage: within 5 business days
- status update: within 10 business days
- dependency checks in CI (
govulncheck, npm audit) - secret scanning in CI (
gitleaks) - request input limits and transport validation