Security fixes are made on the default branch. This project has not yet published a stable compatibility or long-term-support policy.
Use Security → Report a vulnerability in the GitHub repository so details remain private. If private vulnerability reporting is unavailable, open a minimal issue asking the maintainer to establish a private channel; do not include exploit details, credentials, private artifact URLs, or personal data in a public issue.
Include:
- Affected revision and deployment mode
- Reproduction steps or a proof of concept
- Expected and observed impact
- Any suggested mitigation
Do not test against a deployment you do not own or have explicit permission to assess.
Publishing tokens, Lakebed tokens, .env.lakebed.server, .lakebed/, database exports, workspace-viewer invitations, and private artifact URLs must not be committed or included in reports. Rotate a token immediately if it is exposed.