These are personal research, portfolio, and infrastructure projects maintained by one author. There is no commercial support contract or bug-bounty program, but security reports are taken seriously and handled promptly.
- Preferred: open a private vulnerability report via GitHub Security Advisories ("Report a vulnerability") on the affected repository, when enabled.
- Otherwise: reach out through LinkedIn and do not open a public issue that discloses the vulnerability.
Please include the repository, affected version/commit, and reproduction steps. Do not include working exploit payloads against third-party services.
- Supported surface is whatever a repository's README describes as
activeormaintained.case-studyandarchivedrepositories are frozen and are not patched. - No credentials, tokens, or private endpoints should ever appear in these public repositories; if you find one, report it privately so it can be rotated.
- Best-effort acknowledgement within a few days. No SLA is promised.