InfraForge takes security seriously.
If you discover a vulnerability, exposed secret, misconfiguration, or other security concern in any InfraForge-managed repository, please report it responsibly.
Please contact:
Include:
- Repository name
- Description of the issue
- Steps to reproduce, if applicable
- Potential impact
- Suggested fix, if known
- Open a public issue for sensitive vulnerabilities
- Exploit the issue beyond what is needed to verify it
- Access, modify, or delete data that does not belong to you
- Share the vulnerability publicly before we have reviewed it
We aim to review legitimate reports as quickly as possible and prioritize issues based on severity and impact.