Security fixes are applied on the active development and default branches. Production deployments should rebuild the Docker image from the latest committed code and run database migrations as documented.
Do not open a public issue for undisclosed security vulnerabilities.
- Preferred: Use the contact published at
https://<your-site>/.well-known/security.txtwhen the site is deployed (configureSECURITY_TXT_CONTACTand optionallySECURITY_TXT_POLICYin the environment). See ENVIRONMENT.md. - GitHub: If this repository has private vulnerability reporting enabled, use Security → Report a vulnerability.
- Include: affected routes or APIs, reproduction steps, and assessed impact.
We aim to acknowledge valid reports within a few business days.
- PHASE3_OBSERVABILITY_AND_SECURITY.md — headers, auth, rate limits
- TROUBLESHOOTING.md — common operational issues
The public UI is light-theme only; dark mode is not supported or planned for this codebase.