Please do not open public GitHub issues for security vulnerabilities.
Instead, report privately with:
- affected version/commit
- reproduction steps or proof-of-concept
- impact assessment
- any suggested mitigation
Preferred contact: security@phoenixsec.dev
If email is unavailable, open a private advisory through GitHub Security Advisories.
- Initial acknowledgment target: within 72 hours
- Triage and severity assessment: as quickly as possible
- Coordinated disclosure after fix availability
In scope:
- authentication/authorization bypasses
- secret disclosure risks
- cryptographic misuse
- audit integrity issues
- mTLS/certificate trust issues
Out of scope:
- issues requiring local root/system compromise
- purely theoretical findings without realistic impact
- social engineering/phishing