If you believe you have found a security vulnerability in Pulsepass, please do not open a public GitHub issue. Instead, email the maintainer directly at hello@alihamza.dev with:
- A description of the issue.
- Steps to reproduce, or a proof-of-concept if you have one.
- The version / commit SHA you tested against.
You can expect an initial response within a few days. Once the issue is confirmed and a fix is in place, the report will be acknowledged in the release notes (anonymously by default; let me know if you'd like attribution).
This project tracks main only. There are no long-term support branches.
Security fixes land on main directly.
In scope: anything that ships in this repository. Out of scope: vulnerabilities in third-party dependencies — please report those upstream (Laravel, Stripe SDK, Sanctum, etc.).