Email security@celoht.com with a description and reproduction steps. Please don't open a public issue for undisclosed vulnerabilities.
We aim to acknowledge reports within 5 business days.
This repository handles governance, treasury, and program data for CeloHT. In-scope concerns include: RLS policy bypass, auth/session handling, XSS/CSRF in dashboard forms, and dependency vulnerabilities flagged by CodeQL/Dependabot.
Only the main branch receives security fixes.