cue is pre-1.0 and under active development. Only the latest released version receives security fixes.
Please report security issues privately rather than opening a public issue:
- Use GitHub's private vulnerability reporting, or
- email cue@jasoneplumb.com.
Please include steps to reproduce and the affected version or commit. We aim to acknowledge reports within a few days and will coordinate a fix and disclosure timeline with you.
Ride traces contain precise GPS location history. Never commit real ride traces from identifiable people; use synthesized or explicitly consented test traces only (NFR-005).