Security fixes are applied to the default branch (main). Release tags, when
published, receive fixes only for the latest minor line.
Please do not open a public GitHub issue for a suspected vulnerability.
- Open a private report with GitHub Security Advisories.
- Include the affected component (dashboard, backend, contracts, or infra), steps to reproduce, and impact.
- Allow maintainers a reasonable window to confirm and patch before any public disclosure. We aim to acknowledge reports within 5 business days.
If you cannot use GitHub advisories, email the maintainers listed on the repository and encrypt the message with the PGP key below.
Email reports must be encrypted. Use the PGP key published on the repository security advisories page (the same key maintainers use to sign advisory updates):
| Contact | Purpose | Key |
|---|---|---|
| GitHub Security Advisories | Preferred reporting channel | Transport is encrypted by GitHub; no separate key is required |
| Repository maintainers | Fallback email reports | Encrypt to the PGP key linked from the maintainer profile on ceejaylaboratory/AnchorPoint before sending |
Confirm the fingerprint against a key already published by a maintainer. Do not trust a fingerprint pasted into an issue comment.
Do not send exploit proof-of-concept material to public channels. Maintainers will coordinate a fix, credit the reporter unless anonymity is requested, and publish an advisory after a patch is available.