Thank you for taking the time to disclose a security issue responsibly.
If GitHub private vulnerability reporting is enabled for this repository, please use it. It lets you share the report privately with the maintainers without exposing technical details in a public issue.
If private reporting is unavailable, open a regular issue titled security: brief description. Do not include exploit details, proof-of-concept code, credentials, pairing codes, private URLs, tokens, logs containing secrets, or other sensitive information. A maintainer will respond with a private reporting channel.
Please provide enough information for maintainers to understand and investigate the issue:
- A clear description of the issue and its potential impact.
- Minimal steps to reproduce. A complete proof of concept is helpful when safe to share privately, but is not required.
- Affected versions, platforms, or configurations, if known.
- Whether the issue affects the desktop app, bundled middleware, local middleware, Gateway connection, update flow, or another component.
- Whether you would like public credit after a fix has shipped.
Maintainers aim to acknowledge a report within a few days and, for confirmed issues, provide a fix or mitigation plan within about 30 days. Some reports may need more time because of severity, release coordination, or upstream dependency disclosures.
Please do not disclose the issue publicly until the maintainers confirm that a fix or mitigation has been released. If you would like credit, the maintainers can acknowledge your contribution publicly after the fix ships.