Security policy
This repository contains development tools and documentation.
It has no supported application release.
The owner reviews security reports for the current main branch.
Do not include secrets or private simulation inputs in a report.
Use Report a vulnerability to contact the owner, @LukasMosser.
GitHub keeps these reports outside the public issue tracker.
A report needs enough information to reproduce the problem:
- State the affected commit and environment.
- Describe the steps and observed result.
- Explain the affected files, data, or permissions.
- Attach a small example with private data removed.
The owner records security findings in a private advisory. Release notes describe fixes that affect a published release. The project does not promise a response time.