Security fixes are applied to the latest maintained release or the current default branch of each Navanem project. Check the target repository's releases and README for project-specific support information.
Do not open a public issue for a suspected vulnerability.
Use Security → Report a vulnerability in the affected repository to submit a private GitHub Security Advisory. If private reporting is unavailable, email tools@navanem.com with the repository name.
A useful report includes:
- the affected repository, version, package, file, or workflow;
- clear reproduction steps;
- expected impact;
- a safe proof of concept that does not expose personal data or attack third-party systems;
- any suggested mitigation, if known.
Do not test denial-of-service scenarios against live services, access data that is not yours, or publicly disclose an unresolved vulnerability.