Please do not report a security problem via a public issue, a pull request or a discussion. Both routes below reach us privately.
The best option is GitHub’s private vulnerability reporting: open the Security tab of the repository in question and choose Report a vulnerability. The report stays private, you keep a link to the conversation, and a fix can be prepared on a temporary private fork before anything becomes visible.
If you would rather not use GitHub, write to info@acrion.ch. Please say which repository and which version, what an attacker gains, and how to reproduce it. A proof of concept helps and is never required.
No timeline is promised here. acrion innovations is a company of one person, and a promise nobody can keep is worth less than none. Reports are read and they are answered. Where a report is confirmed, we agree a disclosure date with you before anything is published, and you are credited unless you prefer not to be.
Only the latest release of a project receives fixes. There are no maintained branches for older versions.
This repository carries the defaults for every repository that lacks its own. Where a project brings its own security policy, that one applies: it can describe what its attack surface actually looks like, and a policy written for all of them cannot.