Do not open a public issue for a suspected vulnerability.
Use the affected repository's Security tab and choose Report a vulnerability when private Security Advisories are enabled. If that option is unavailable, email support@ultima.inc.
Include, where safe:
- the affected repository, version, release, or commit;
- a concise description and expected impact;
- reproducible steps or a minimal proof of concept;
- relevant platform and runtime details; and
- a safe way to follow up with you.
Do not include live credentials, access tokens, customer data, health data, or other personal data. Use placeholders and redact logs or screenshots.
We will keep the report in the private channel, acknowledge it there, validate and triage the issue, and coordinate remediation and disclosure with the reporter. Public disclosure should wait until a fix or mitigation is available and affected parties have had a reasonable opportunity to update. Reporters may request credit or anonymity.
Repository-specific SECURITY.md files override this default when a project has a more specific trust model or reporting process.