If you believe you have found a security vulnerability in MyAPES Core (APESCIC/MyAPES-Account), report it privately so repository administrators can review it before any public disclosure.
Use GitHub private vulnerability reporting:
That form creates a private security advisory visible only to repository administrators. You can also open Security → Advisories → Report a vulnerability on this repository.
Do not open a public GitHub issue, discussion, or pull request for a suspected vulnerability. Do not describe suspected vulnerabilities in the public Change Log Hub or in public release notes.
This repository does not publish a separate security-contact email. GitHub private vulnerability reporting is the supported path to repository administrators.
Please include:
- A short description of the issue and its impact
- Steps to reproduce, or a proof of concept, if you have one
- Affected versions or environments, if known
- Any suggested mitigation
Do not include credentials, personal data, or production secrets in the report.
Security reports are accepted for the current released MyAPES Core version on main (see VERSION). Older beta versions may not receive a separate patch.
Use public issues only for non-security bugs and feature requests. The Change Log Hub records released, public-safe changes. It is not a channel for vulnerability reports.