Please do not disclose suspected vulnerabilities in a public issue or pull request. Report them privately through the repository's Security tab using GitHub's private vulnerability reporting flow.
Include the affected client and Hubuum server versions, reproduction steps, the expected and observed behavior, and any known mitigations. Do not include real credentials, access tokens, or production data.
Maintainers will acknowledge a complete report, assess affected versions, and coordinate remediation and disclosure through the private advisory.
Until the first stable release, security fixes are made on the latest published
0.0.x release. Users should upgrade to the newest available version.