If you discover a security issue in DotReport, please do not open a public issue.
Instead, report it privately through GitHub's Report a vulnerability feature or contact me directly through Discord (@ottergrl.) or email (yy@deranged.network).
Please include as much information as possible:
- A description of the issue.
- Steps to reproduce it.
- The potential impact.
- Any suggested fix, if you have one.
I will acknowledge reports as soon as reasonably possible and work toward a fix if the issue is confirmed.
This project does not publish compiled binaries or official releases. Users are expected to build the application from source.
Security reports are most helpful when they involve issues in the project's source code, server-side behavior, configuration handling, or dependency usage.
Because the project does not maintain versioned releases, security fixes are applied to the current main branch.
If a vulnerability is fixed, users should update to the latest commit.