Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them via email to: security@allcontext.dev
You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
Please include the following information:
- Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the issue
- Location of affected source code (tag/branch/commit or direct URL)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue
We prefer all communications to be in English.
- We will acknowledge receipt within 48 hours
- We will confirm the vulnerability and determine its impact
- We will release a fix as soon as possible
- We will credit you in the security advisory (unless you prefer to remain anonymous)
If you have suggestions on how this process could be improved, please submit a pull request or open an issue.