Report security concerns to info@tmhsdigital.com (same contact as the Code of Conduct).
Please do not open public GitHub issues for undisclosed vulnerabilities.
Security fixes are applied to the latest release on the default branch. Older tagged releases may not receive patches.
This project does not currently operate a formal coordinated vulnerability disclosure (CVD) program beyond email intake. Maintainers will acknowledge reports and work with reporters on a reasonable timeline.
This is a public repository. Do not commit:
- API keys, tokens, or passwords
- Private configuration or customer data
- Signed executables or binaries except through the release pipeline
If sensitive data is committed accidentally, contact the maintainers immediately so the history can be addressed.
This is an input-automation tool. Reports of unsafe defaults, privilege issues, or supply-chain problems in the release pipeline are in scope; “how do I abuse this against a third party” is not.