Security fixes are applied to the latest release and the default branch. Older deployments should upgrade before requesting support.
Do not open a public issue for a vulnerability. Email ulofi@ulofi.com with:
- the affected component and version;
- reproduction steps or a minimal proof of concept;
- the expected and observed security boundary;
- any suggested mitigation.
Do not include live credentials, personal data, production database contents, or data belonging to other Discord members. Use obvious test values and redact request headers, tokens, cookies, and identifiers.
If the report is valid, maintainers will coordinate a fix and disclosure before publishing technical details. Please avoid accessing data that is not yours or disrupting a live community while testing.