Thank you for helping keep Justagwas projects and their users secure.
For projects with published releases, security fixes are provided for the latest stable release line. For projects without numbered releases, the current default branch is the supported version. Archived repositories and superseded releases do not ordinarily receive security updates.
Do not disclose a suspected vulnerability through a public issue, discussion, pull request, or social-media post.
Use GitHub's private vulnerability-reporting feature for the affected repository when it is available. Otherwise, email email@justagwas.com.
Include, where possible:
- The affected project and version or commit.
- A clear description of the issue and its potential impact.
- Reproduction steps or a minimal proof of concept.
- Relevant configuration and environmental details.
- A suggested mitigation, if one is known.
Do not include credentials, access tokens, personal data, or unrelated private information.
- An initial response is targeted within seven days.
- Reports are assessed according to reproducibility, impact, and severity.
- Additional information may be requested during investigation.
- Public disclosure is coordinated after a correction or practical mitigation is available.
- Reporter credit is provided when requested, unless anonymity is preferred.
Complex reports may require more time to investigate and resolve. Please allow a reasonable opportunity to address the issue before publishing details.
Crashes, incorrect output, compatibility problems, and other defects without a security impact should use the repository's normal issue tracker.