Do not disclose suspected vulnerabilities, secrets, authentication codes, cookies, personal data, or production configuration in a public issue.
Use GitHub's private vulnerability-reporting or private security-advisory channel for this repository when available. If that channel is unavailable, contact the project owner through an established private CalorieToken contact channel and share only the minimum information needed to establish a secure reporting path.
Current V2 scope is the non-financial, non-custodial CalorieApp food and nutrition application, including its backend, frontend, and separately licensed WordPress identity bridge.
Reports involving wallet custody, private keys, payments, token transfers, trading, or other financial execution are outside the implemented product unless they demonstrate that such functionality is unexpectedly present.
Never include real secrets, credentials, private keys, seed phrases, database contents, authorization codes, session cookies, or unnecessary personal data in a report. Redact logs and screenshots.
Repository checks reject tracked private age identities, literal Neon API-key
assignments, credential-bearing Neon database URLs and provider backup
artifacts. Only the approved public age recipient may later be committed.
These pattern checks supplement provider-side secret scanning; they do not make
the repository an approved place to generate, decrypt or temporarily store a
private identity.
This policy does not grant permission for destructive testing, denial of service, social engineering, privacy violations, accessing other users' data, or testing third-party systems such as WordPress, Xaman/XUMM, Open Food Facts, or Render without their authorization.
No bug-bounty payment or reward is promised unless separately agreed in writing.