Do not disclose a vulnerability, credential, customer detail, internal infrastructure fact, or unsafe publication in a public issue or discussion.
Use GitHub private vulnerability reporting for this repository:
https://github.com/lightning-it/documentation/security/advisories/new
Include the affected path or commit, impact, safe reproduction information, and suggested remediation. Do not include live credentials or protected customer data; identify the approved secure exchange channel needed for those details.
Reports may cover the site source, custom components, build/deployment chain, dependencies, response-header policy, or accidental sensitive publication. General product support belongs in the support channels described in SUPPORT.md.
Maintainers will triage privately, preserve relevant evidence, remove exposed public material when necessary, rotate or revoke affected credentials through the owning secret system, assess Git history and deployment caches, and publish an appropriately sanitized advisory when disclosure is safe.
No response-time or certification claim is made in this public policy.