Report suspected vulnerabilities privately so we can investigate before disclosure.
Do not open a public issue. Email security@heyrafiki.space with:
- the repository and version affected
- what an attacker could do with it
- the steps to reproduce
- a proof of concept, if you have one
We acknowledge reports within 14 days and provide status updates until resolution.
Give us time to investigate and ship a fix before you publish. We will keep you updated while we work, and we credit reporters by name unless you would rather we did not.
Send the minimum needed to explain the problem. Never include real personal or health data in a report or a proof of concept. If a vulnerability exposes real records, tell us what you found and stop there. Do not download, keep or share them.
Automated scanner output with no demonstrated impact, missing headers with no exploit path, and findings that require an already-compromised device or account.