The maintainers review reports for the latest released version of Gyro API. Earlier versions may not receive fixes. No public release has been made yet.
Do not open a public issue or pull request with exploit details. If this repository has GitHub private vulnerability reporting enabled, use Security > Report a vulnerability. Otherwise, email kavrindev@gmail.com with the subject Gyro API security report.
In the first message, describe the affected version, impact, and steps to reproduce. Do not send production credentials, personal data, or a live exploit against the hosted service. The maintainers can arrange a safer way to exchange sensitive evidence if needed. Please allow time for investigation before public disclosure.
The maintainers will acknowledge and triage reports when they can. This policy does not promise a fixed response time or a bug bounty. Security reports about the hosted Gyro service use the same private route; source-code issues and production incidents may need different remedies.