Please report vulnerabilities privately to ride@velorki.com or through GitHub's private vulnerability reporting on this repository. Do not open a public issue for security problems.
What is in scope: the app, the website and relay (web/), the self-hosting assets, and the
official services at velorki.com. Please do not test against the official
services with automated tools; run your own instance from deploy/.
We acknowledge reports within 7 days and aim to fix confirmed issues in the next release. Credit is given in the release notes if you want it.