Report vulnerabilities through GitHub private vulnerability reporting. If that channel is unavailable, open an issue asking for a private contact without including exploit details, credentials, or sensitive logs.
Keep vulnerability details private while the maintainer investigates and coordinates a fix and disclosure.
Distroplane is pre-1.0. Security fixes target the latest development line; older release candidates have no maintenance commitment.
See the security model for provider trust, credential handling, verification, and accepted risks.