The mecatl community takes security seriously. We appreciate responsible reports that help protect users and operators.
Please do not report security vulnerabilities in public GitHub issues. Report them privately through GitHub Security Advisories using Report a Vulnerability.
If you cannot access GitHub, email security@stacklok.com. Include steps to reproduce the issue, affected versions, and any files needed to reproduce it. If you need to use GPG, first email to request a public PGP key.
We ask reporters to use coordinated, private disclosure until a fix or mitigation is available. If you know of a publicly disclosed vulnerability, please notify security@stacklok.com promptly so we can assess and address it.
The security team will coordinate investigation, remediation, and public communication as appropriate for the vulnerability. For non-security bugs and contributions, see CONTRIBUTING.md.