Security fixes are made on the current release line. Users should reproduce a report against the latest published 1.x version before filing it when practical.
Do not open a public issue for a suspected vulnerability. Email
arda@ardasevinc.com with:
- the affected ccm version and operating system
- a minimal reproduction or proof of concept
- the expected and observed behavior
- the impact you believe the issue has
Avoid including real credentials, authentication files, or private configuration in the report. A fix and disclosure timeline depends on the severity and complexity of the report.