Report suspected vulnerabilities through GitHub's private vulnerability reporting for this repository. Do not open a public issue, discussion, or pull request containing exploit details, credentials, personal data, or reproduction steps that could put the live SAL platform at risk.
The diese-tech maintainer will acknowledge a complete report within three business days. The acknowledgement is not a resolution deadline; remediation timing depends on severity, impact, and the safety of the rollout.
Include the affected component, impact, minimum reproduction steps, and any suggested mitigation. Use placeholder credentials and redact production identifiers.
If private vulnerability reporting is unavailable, open a public issue that asks the maintainer to establish a private contact channel without including vulnerability details.
Security fixes target the current main branch and the currently deployed release. Older commits and historical audit snapshots are not supported versions.