If you discover a security vulnerability in Barnacle, please do not open a public GitHub issue. Instead, report it privately by emailing security@enricai.com. We will acknowledge receipt within 3 business days and aim to provide a fix or mitigation timeline within 14 days of confirmation.
When reporting, please include:
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof-of-concept if available.
- The affected version (commit SHA or release tag).
Coordinated disclosure is appreciated — please give us a reasonable window to ship a fix before publishing details.