Security reporting
Current contact boundary
Section titled “Current contact boundary”The public site does not currently publish an approved security-reporting endpoint or email address. Do not send sensitive details to an address guessed from a domain, repository, or example.
Until an approved endpoint is available
Section titled “Until an approved endpoint is available”Do not include credentials, private keys, Wi-Fi passwords, live device IDs, private hostnames, operator recovery locations, or active incident data in a public issue or pull request. Preserve only the minimum sanitized information needed to reproduce a concern, and keep any private evidence local until the owner publishes an approved channel.
When a private channel is supplied, report the affected component and exact immutable version, impact, reproduction steps, expected and observed behavior, and whether the issue is local-only or cloud-enabled. Redact secrets and use placeholders for all identifiers. Do not probe or disrupt systems you do not own.
This page is guidance, not a response-time promise, legal statement, or guarantee that a report can currently be received.
