Please do not open a public issue for a suspected vulnerability.
Use GitHub's Security → Report a vulnerability flow so the report and any follow-up remain private until a fix is available. Include the affected component, reproduction steps, impact, and any suggested mitigation.
SupaMail handles mailbox credentials and message data. Do not include real credentials, tokens, private email content, or customer data in a report.
SupaMail is pre-1.0. Security fixes are applied to the latest commit on main;
older commits and container images are not maintained as separate release
lines.