Please do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities through GitHub Security Advisories:
https://github.com/menvil/rateguru/security/advisories/new
Include:
- Affected feature or component.
- Steps to reproduce.
- Expected impact.
- Any proof-of-concept details that help verify the issue.
No project PGP key is published yet. If encrypted disclosure becomes required, request a secure contact path through the advisory.
- Initial acknowledgement target: within 3 business days.
- Triage target: within 7 business days.
- Fix and coordinated disclosure target: depends on severity and scope.
Please allow maintainers time to investigate and release a fix before public disclosure.