Do not disclose suspected vulnerabilities in public GitHub issues, discussions, pull requests, or commit messages.
Use GitHub Private Vulnerability Reporting for the affected repository whenever
it is available. If private reporting is unavailable, contact Runovel at
info@runovel.com with the repository name, affected version, impact, and safe
reproduction details.
Before sharing diagnostics, redact credentials, tokens, private keys, personal data, public or private IP addresses that identify an environment, hostnames, routes, configuration files, database contents, and customer or provider data. Never attach production secrets. Use minimal synthetic examples where possible.
Runovel will acknowledge reports on a best-effort basis, validate the issue, coordinate remediation, and publish disclosure information when it is safe to do so. Individual repositories may document a more specific support policy.
Each project documents its supported versions and security-update policy in its own repository. Unless stated otherwise, only the latest stable release should be assumed to receive security fixes.