If you discover a security vulnerability, please follow the process below to report it responsibly.
Avoid posting details about the issue in public repositories, issues, or discussions.
Premature disclosure could expose users to unnecessary risk.
Send an email to our dedicated security team:
Please include:
- A detailed description of the vulnerability
- Steps to reproduce
- The affected component (frontend, backend, API, etc.)
- Expected and actual behavior
- Possible impact and suggested fixes (if applicable)
- We will acknowledge your report within 48 hours.
- You’ll receive a progress update within 5 business days.
- Once verified, we’ll work on a patch and coordinate a responsible disclosure timeline.
- You’ll be notified when the issue has been resolved and released.
Please do not share information about the vulnerability until a fix is publicly available.
Coordinated disclosure helps keep all users secure.
Valid vulnerability reporters may be credited in the project’s release notes, unless anonymity is requested.
- Only active and LTS branches receive security updates.
- Older versions (marked ❌) are unsupported.
- Always use the latest Docker images, dependencies, and environment variables.
- If you deploy this project in production, ensure you have proper network isolation, TLS, and access controls in place.
🪪 Contact: suaybdemir1@gmail.com