Skip to content

Latest commit

 

History

History
7 lines (4 loc) · 995 Bytes

File metadata and controls

7 lines (4 loc) · 995 Bytes

Security policy

Report suspected vulnerabilities privately using the Report a vulnerability option on the affected repository's GitHub Security tab when available. If private reporting is unavailable, email hello@rexcode.co.uk with the repository name and a concise description. Do not post vulnerability details in a public issue, pull request, or discussion.

Do not include credentials, access tokens, customer or merchant data, private URLs, production configuration, or unredacted logs in an initial report. Provide an affected version or commit, impact, and a minimal sanitised reproduction where possible; request a suitable private channel before sending sensitive evidence.

Maintainers will acknowledge and assess reports as reasonably practicable. No response-time commitment is made here. Coordinate disclosure with the repository maintainers while an issue is being assessed. A repository-specific security policy takes precedence when present.