Please do not open a public GitHub issue for security vulnerabilities.
Email security reports to: security@caldera.dev (or open a GitHub private security advisory).
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
We will acknowledge within 48 hours and aim to release a fix within 90 days.
- Token encryption bypass
- Authentication / authorization bypass
- Webhook HMAC verification bypass
- Credential exposure in logs or API responses