Do not open a public GitHub issue for security vulnerabilities.
Report privately to: blackcatacademy@protonmail.com
Include, when possible:
- affected component/process (
registry,site,catalog,access, or shared libs) - impact and severity estimate
- minimal reproduction or failing payload
- suggested fix or mitigation (optional)
Security fixes are provided for the latest stable release and the active development branch.