Security Policy
Supported version
Security fixes are applied to the main branch.
Reporting a vulnerability
[!CAUTION] Do not report vulnerabilities, leaked credentials, or exploitable details in a public issue or discussion.
Use GitHub private vulnerability reporting to contact the maintainers privately.
If private vulnerability reporting is unavailable, contact GitHub Support and request a private route to the paulasilvatech organization. Do not disclose exploit details publicly.
Include:
- the affected path and commit;
- reproducible steps in a disposable environment;
- expected and observed behavior;
- potential impact;
- a minimal proof of concept when safe;
- any proposed mitigation.
Educational content
Documentation inaccuracies, stale links, and non-sensitive lab failures can use the public bug report template.
Never include real API keys, access tokens, customer data, private source code, or production endpoints in a report.