If you discover a security issue, do not open a public GitHub issue.
Please report it privately to: support@dineros.cc
Include:
- a clear description of the issue;
- reproduction steps or proof of concept;
- affected files/endpoints;
- impact assessment if known.
- We will acknowledge receipt as soon as possible.
- We will investigate and triage based on severity and exploitability.
- We may ask for additional details to validate the report.
- Please do not publicly disclose vulnerabilities until a fix is released or we explicitly approve coordinated disclosure.
- We appreciate responsible disclosure and good-faith research.
- Never include real credentials, API keys, tokens, or personal data in reports.
- Redact secrets from screenshots and logs.
- If you discover exposed secrets in commit history, tags, cached artifacts, or archived releases, report them through this process.
Security fixes are applied to the active main branch.
Older commits and forks are not guaranteed to receive patches.
This repository is actively moving toward stronger public-repo safeguards, including secret hygiene and key exposure review.