Please do not report security vulnerabilities through public GitHub issues.
Use one of these private channels instead:
- GitHub private vulnerability reporting, if enabled for this repository
- Email: jp@trailscoffee.com
Include a short description, impact, affected version or commit, reproduction steps, and whether you believe funds, credentials, private keys, customer data, or production infrastructure are at risk.
Security-sensitive reports include authentication bypass, secret exposure, payment or wallet flaws, server-side request forgery, injection, cross-site scripting, dependency-chain compromise, authorization mistakes, and ways to access data outside the intended user or store boundary.
We aim to acknowledge credible reports within 72 hours. Please give us a reasonable remediation window before public disclosure, especially where customer data, credentials, private keys, Bitcoin/Lightning funds, or operational infrastructure could be affected.
Do not include real API keys, tokens, Nostr private keys, wallet seeds, macaroons, database dumps, customer data, or production logs in issues, pull requests, screenshots, or test fixtures.