This project is maintained on a best-effort basis.
Security fixes, when available, are provided for the latest release and the main branch.
If you believe you’ve found a security vulnerability, please report it privately using GitHub’s security advisory / private vulnerability reporting for this repository:
- Go to: https://github.com/johansabent/gh-discussion/security
- Click “Report a vulnerability” (if available)
Please include:
- A clear description of the issue and impact.
- Steps to reproduce or a proof-of-concept.
- Affected versions / commit SHA, if known.
- Any suggested mitigation.
If you can’t use the private reporting flow, open a GitHub issue.
- Do not include sensitive details (exploits, secrets, tokens, full PoCs).
- Use a title prefix like:
[SECURITY] <short summary> - I will follow up in the issue thread to coordinate next steps.
- I’ll acknowledge reports as soon as practical (best-effort; this is a hobby/open-source project).
- If the report is accepted, I’ll work on a fix and publish a release.
- Please avoid public disclosure until a fix is available (or we agree otherwise).