Thank you for helping keep my projects and their users safe. This policy applies to
all of my public repositories that do not define their own SECURITY.md.
Many of these projects are unofficial, community-maintained integrations or tools and are not affiliated with the vendors whose products or services they interact with. Vulnerabilities in a third party's cloud service, firmware, or applications should be reported directly to that vendor.
Security fixes are provided for current releases only. Older versions are not patched — please update to the latest release before reporting.
| Version | Supported |
|---|---|
| Latest stable release | ✅ |
| Latest beta release | ✅ |
| Any older release | ❌ |
Please do not open a public GitHub issue for security vulnerabilities. Public issues can expose users before a fix is available.
Instead, report privately by reaching out to me directly:
- Discord or LinkedIn — contact details are listed on my GitHub profile: @JeffSteinbok
When reporting, please include as much of the following as you can:
- The affected repository and the version you're running
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept, logs, or configuration if relevant)
- Any suggested remediation, if you have one
Please redact credentials, tokens, and other sensitive data from anything you share.
- I'll acknowledge your report as soon as I reasonably can.
- I'll investigate and keep you updated on progress toward a fix.
- Once a fix is released, I'm happy to credit you for the discovery — let me know if you'd prefer to remain anonymous.
Thanks for reporting responsibly. 🙏