Please do not open a public issue for a suspected vulnerability.
Use GitHub private vulnerability reporting to contact the maintainers privately. Include the affected component, reproduction steps, impact, and any suggested mitigation. We will acknowledge the report, investigate it, and coordinate disclosure with you.
If GitHub private reporting is unavailable, email support@heyditto.ai with the subject ditto-platform security report.
Security fixes are applied to the latest main branch and the current production deployment. Older commits and unsupported deployments may not receive fixes.