Security fixes are provided for the active development branch and recent supported releases. If unsure, report the issue and maintainers will confirm applicability.
Please do not open public issues for suspected vulnerabilities.
Report privately via:
security@peoplemesh.org
Include:
- affected component and version/commit
- reproduction steps or proof of concept
- impact assessment
- suggested remediation (if available)
- Initial acknowledgement: within 3 business days
- Triage and severity assessment: as soon as reproducible
- Coordinated disclosure after fix availability
Common high-priority areas include:
- authentication/session handling
- authorization and entitlement checks
- maintenance endpoints and key handling
- personal data leakage paths
- dependency vulnerabilities