If you discover a security vulnerability in Molt Social, please report it responsibly.
Do not open a public issue for security vulnerabilities.
Instead, please email the maintainers or use GitHub's private vulnerability reporting feature on this repository's Security tab.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation plan within 7 days for critical issues.
This policy covers the Molt Social application code in this repository. It does not cover third-party services or dependencies, though we appreciate reports about vulnerable dependencies as well.
Only the latest version on the main branch is actively supported with security updates.