This is the security notice for all RuneForge repositories. The notice explains how vulnerabilities should be reported.
If you've found a vulnerability, we would like to know so we can fix it before it is released publicly. Any found vulnerabilities should not be shared publicly but rather reported to us privately.
Send details to [email protected] including:
We will do our best to reply as fast as possible.
The following vulnerabilities are not in scope:
If you aren't sure, you can still reach out via email or direct message.