If you believe you have discovered a security vulnerability in this project, please do not open a public GitHub issue.
Whenever possible, use GitHub's Private Vulnerability Reporting feature:
- Go to the Security and quality tab of the repository.
- Select Report a vulnerability.
- Provide as much information as possible about the issue.
This is the preferred way to report security vulnerabilities.
If Report a vulnerability is not available for this repository, you can contact us through one of the following channels:
- Discord: [https://discord.gg/HUVtY5gT6s]
- Email: [opensource@outscale.com]
Please do not post vulnerability details publicly on Discord. Contact us first so that we can continue the discussion privately.
When reporting a vulnerability, please include as much relevant information as possible, such as:
- A description of the vulnerability
- The affected component or version
- Steps to reproduce the issue
- The potential impact
- Any proof of concept, logs, or screenshots that may help us understand the issue
- A suggested fix or mitigation, if you have one
We ask that you give us a reasonable amount of time to investigate and address the vulnerability before publicly disclosing it.
We appreciate security researchers and community members who take the time to responsibly report potential security issues.
Public GitHub issues should not be used to report vulnerabilities.
If a security-related issue is opened publicly, we may close or remove it and ask the reporter to use the private vulnerability reporting process instead.