Miadi-18

Security reporting

Report suspected vulnerabilities through GitHub private vulnerability reporting. Include the affected commit or package version, deployment mode, impact, and a minimal reproduction using synthetic data. Never include live credentials or community records.

Keep exploit details, sensitive file locations, and credential evidence out of public issues. Public tracking issue #657 contains the remediation plan; maintainers handle detailed evidence privately. A scanner finding alone does not establish exploitation or a breach.

The current source tree is under active security review. Published packages and deployed services may differ from main; report the actual installed version. No historical release is assumed safe solely because it remains available.

Operators should follow the deployment notes, verify both public and VPN access, and rotate confirmed exposed credentials at their issuer. Removing a credential from a file does not revoke it.