Lineweb Social is currently available as a public beta. Security fixes are
provided on a best-effort basis for the latest 0.2.x beta and the
main branch only.
Report vulnerabilities through GitHub private vulnerability reporting rather than a public issue. Include the affected version or commit, reproduction steps, impact, and any suggested mitigation. Do not include real user data or credentials.
Security-sensitive areas include authorization boundaries between spaces, authentication and account recovery, private messaging, uploaded media, extension installation, webhooks, exports, and deletion workflows.
No bounty program or guaranteed response-time commitment exists. Production operators should evaluate the code, configure infrastructure securely, and track every beta update until a stable release policy is published.