Do not open a public issue for a security problem. A public reproduction is a working exploit handed to everyone running n8Tracks.
Report privately through GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Choose Report a vulnerability.
- Describe the problem, the affected version or commit, and how to reproduce it.
n8Tracks is maintained by one person in their spare time. Reports are read and answered on a best-effort basis; there is no guaranteed response or fix timeline. You will be credited in the published advisory unless you ask not to be.
Security findings, whether reported externally or found by the project's own audits, are tracked as draft GitHub security advisories. They are visible only to maintainers until a fix is available, and are then published.
The project is pre-release. Only the latest commit on main is supported.