Security fixes are prepared against main.
Please do not open public GitHub issues for security vulnerabilities.
If GitHub private vulnerability reporting is enabled for this repository, use that channel. Otherwise, contact the maintainer privately before public disclosure and include:
- a description of the issue
- affected routes, scripts, or features
- reproduction steps or proof of concept
- impact assessment if known
We will acknowledge credible reports, assess severity, and coordinate remediation before public disclosure.
This repository contains application code, deployment automation, and operational scripts. Reports that affect authentication, tenant isolation, deployment credentials, background jobs, or document generation should be treated as high priority.