Security fixes are applied to the latest published version of each Lumen package. Upgrade to the latest release before reporting an issue that may already be fixed.
Do not open a public issue for a suspected vulnerability. Use GitHub's
private vulnerability reporting to
share the affected package and version, reproduction steps, impact, and any suggested mitigation.
If private reporting is unavailable, email support@santi020k.com without including secrets or
personal data.
You should receive an acknowledgement within seven days. Confirmed reports will be investigated, fixed in the affected packages, and disclosed through a GitHub security advisory when appropriate.
Accessibility defects and general bugs are important, but they are not security vulnerabilities unless they also create a confidentiality, integrity, or availability risk. Report those through the public issue tracker.