Please do not file public GitHub issues for security vulnerabilities.
If you discover a security vulnerability in Vandalizer, please report it responsibly using GitHub Security Advisories.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- 48 hours - Initial acknowledgment of your report
- 1 week - Assessment and severity determination
- 90 days - Coordinated disclosure window
We will work with you to understand and address the issue before any public disclosure.
Security updates are applied to the latest release on the main branch.