This policy covers the AMoon Eclipse public repository, hosted services, and self-hosted deployments based on this codebase.
If you find a security issue, report it privately through the repository owner or the official contact channel for the deployment. Do not open a public issue for active vulnerabilities.
Include:
- a short description of the issue
- affected component or path
- reproduction steps
- impact summary
- any proof of concept, if available
Please avoid:
- credential theft
- destructive testing
- data exfiltration
- public disclosure before a fix is available
I will acknowledge the report, verify impact, and coordinate a fix or mitigation. If the issue affects a deployed service, the response will focus on containment first, then patching.
After a fix is ready, coordinated disclosure is preferred. If a deployment has its own policy, follow the deployment operator's process as well.