We take the security of CosmicBytez projects seriously and appreciate responsible disclosure.
Please do not report security vulnerabilities through public GitHub issues.
Instead, use one of these channels:
- GitHub private vulnerability reporting (preferred) — use the Report a vulnerability button under the Security tab of the affected repository.
- Email — azullus@cosmicbytez.ca with the subject line
[SECURITY] <repo name>.
Please include:
- The affected repository and version/commit
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept code is welcome)
- Any suggested remediation, if you have one
- Acknowledgement of your report within 72 hours
- An assessment and expected timeline within 7 days
- Credit in the release notes when a fix ships (unless you prefer to remain anonymous)
All public repositories under the CosmicBytez organization are in scope.
Thank you for helping keep our tools and their users safe.