Security fixes are applied to the version deployed at
cali.so. The current v3 release is supported on main;
unreleased integration work is supported while it remains on active dev or
pull-request branches.
Use GitHub's Security tab and choose Report a vulnerability. Do not open a public issue, discussion, or pull request for a suspected vulnerability, and do not include exploit details in public project updates.
Please include the affected surface, a minimal reproduction, impact, and any suggested mitigation. Remove credentials, personal data, private content, payment data, meeting details, and raw provider payloads from the report. If a demonstration needs sensitive evidence, describe how to reproduce it without attaching live data.
Please allow time to investigate, remediate, deploy, and notify affected users before publishing details. We will coordinate a disclosure date with the reporter when public disclosure is appropriate. We may ask that details remain private longer when a fix depends on an upstream provider or a safe migration.
Good-faith research should avoid privacy violations, service disruption, social engineering, persistent access, data destruction, and access beyond the minimum needed to demonstrate the issue. If you encounter user data or a live credential, stop and report it privately.