Please do not report security vulnerabilities in public issues.
If you believe you have found a vulnerability in a Tutti OS project, contact the maintainers privately with:
- the affected repository and version or commit;
- a description of the issue;
- reproduction steps or proof of concept;
- potential impact;
- any suggested mitigation.
We will acknowledge reports as quickly as possible and coordinate next steps.