Security

Use the repository's private vulnerability reporting form when it is available. If the organization repository has not opened yet, contact a ShruggieTech maintainer privately and do not create a public issue.

Include the affected revision, platform, file type or input, reproduction steps, impact, and any proof-of-concept material needed to validate the report. Remove personal or unrelated confidential data before submitting files.

Maintainers will acknowledge a complete report, assess severity and affected versions, coordinate remediation, and credit reporters who request attribution when disclosure is safe. Response timing depends on severity, reproducibility, and release readiness; maintainers will communicate concrete status rather than promise a fixed deadline before triage.

Do not disclose vulnerabilities in a public issue.