Security fixes are applied to the latest code on the main branch.
Please do not open public issues for security vulnerabilities.
Instead:
- Open a private security advisory on GitHub (preferred), or
- Contact project maintainers directly via GitHub.
When reporting, include:
- A clear description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested mitigation (if known)
You can expect:
- Initial acknowledgement within 72 hours
- Status updates as triage progresses
- Coordination on responsible disclosure before public release
Security reports are especially helpful for:
- Authentication/session handling
- Firestore credential handling
- Secrets leakage
- API abuse or injection vectors
- Dependency vulnerabilities
Thank you for helping keep FilmRoll and its users safe.