Configator loads configuration and secrets for downstream applications, so we take security reports seriously.
Do not open a public issue for security vulnerabilities.
Report privately through GitHub's private vulnerability reporting on this repository: go to the Security tab and click Report a vulnerability. This opens a confidential advisory visible only to you and the maintainers.
If you cannot use GitHub advisories, email contact@utiligize.com instead.
Please include enough detail to reproduce the issue: affected version, a description of the impact, and steps or a proof of concept. We aim to acknowledge reports within five business days and will keep you informed as we work on a fix.
Only the latest released version receives security fixes. Fixes are shipped in a new release rather than backported; upgrade to the most recent version to stay protected.