We appreciate your efforts in responsibly disclosing your security findings.
To report a security vulnerability:
- DO NOT create a public GitHub issue for the vulnerability!
- DO NOT create a public GitHub discussion for the vulnerability!
- DO NOT discuss the vulnerability in public spaces like X or Discord!
- DO NOT create a public GitHub Pull Request with a fix for the vulnerability!
- Send an email to
security@papercompute.com. - Include the following details in your report:
- Description of the vulnerability and project.
- Steps to reproduce.
- Any mitigations or fixes you've already identified.
Allow up to 7 days for an initial response and acknowledgement. We will provide our own analysis and security audit at which time we will determine if the vulnerability can be exploited. We will also then provide a timeline for a fix.
(Optional) If you already have a fix and would like to contribute your patch,
please work directly with our team via security@papercompute.com
to coordinate pushing the patch to GitHub,
cutting a new release,
and disclosing the change.
Thank you!