Please report security vulnerabilities privately rather than opening a public issue.
Use GitHub's private vulnerability reporting: go to the Security tab and open a draft advisory. This keeps the report confidential until a fix is released.
If you cannot use that mechanism, email security@de-otio.org.
Please include enough detail to reproduce the issue (affected package and version, a minimal proof of concept, and the impact you have in mind).
This project is published mainly for inspection and is maintained on a best-effort basis under time constraints, so security reports are handled as time permits — acknowledgement may take a while. Reports are still welcome and read; please just don't expect a same-week turnaround.
These packages are pre-1.0 and released together from this monorepo. Only the latest published version of each package receives security fixes:
@de-otio/saas-foundation@de-otio/saas-foundation-cdk@de-otio/vestibulum@de-otio/vestibulum-cdk
We follow coordinated disclosure: we will work with you on a fix and a release before any public details are published, and will credit reporters who wish to be acknowledged.