Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately using one of these channels:
- GitHub private advisory (preferred): use the Report a vulnerability button under the repository's Security tab.
- Email: info@disscount.me
Please include as much detail as you can:
- The type of issue (for example: authentication bypass, injection, XSS).
- The affected component (frontend, backend, an API endpoint) and version or commit.
- Steps to reproduce, and a proof of concept if possible.
- The potential impact.
- We aim to acknowledge your report within a few days.
- We will keep you informed as we investigate and work on a fix.
- Please give us reasonable time to release a fix before any public disclosure.
We appreciate responsible disclosure and will credit reporters who wish to be acknowledged.