Do not report vulnerabilities in public issues.
Report privately: security@swobu.com
Include the following:
- affected version or commit
- impact
- reproduction steps
- proof of concept, if safe to share
- suggested fix, if known
We will review valid reports and coordinate disclosure.
Security reports may include:
- authentication or authorization flaws
- data exposure
- secret leakage
- remote code execution
- dependency vulnerabilities with practical impact
- unsafe defaults
- privilege escalation
- supply-chain risks
Out of scope:
- spam
- social engineering
- denial-of-service attacks without practical exploit detail
- vulnerability scanner output without analysis
- reports requiring access to private customer data
We will not pursue legal action for good-faith security research that:
- avoids privacy violations
- avoids data destruction
- avoids service disruption
- avoids accessing or modifying data that is not yours
- gives us reasonable time to investigate before public disclosure