If you discover a security vulnerability in YAP, please do not report it publicly as a GitHub issue.
Instead, use GitHub's Private Vulnerability Reporting to report it privately to the maintainers.
When reporting a vulnerability, please include:
- A description of the vulnerability
- Steps to reproduce it
- The affected version or commit
- Any relevant logs, screenshots, or proof-of-concept code
We will investigate reported vulnerabilities and work to fix them as quickly as reasonably possible.
YAP is currently under development, so security support is provided for the latest version of the project.
Older versions may not receive security fixes.
Please allow reasonable time for a vulnerability to be investigated and fixed before publicly disclosing it.
Security fixes may credit the person who reported the vulnerability, unless they request to remain anonymous.