Please do not open a public GitHub issue for security vulnerabilities.
Instead, report details privately to the maintainers (use repository contact options if available, or open a private security advisory via GitHub if enabled for this repository).
Include:
- A short description of the issue and its impact
- Steps to reproduce or a proof of concept, if possible
- Affected versions or commits, if known
We will work with you to understand and address the report before any public disclosure.
This policy applies to the Parbin application code in this repository (frontend, backend, and local development configuration). Third-party dependencies are tracked via package.json, pnpm-lock.yaml, and go.mod / go.sum; keep them updated as part of routine maintenance.