If you discover a security vulnerability in Linkdirecte, please do not open a public issue or PR.
Instead, email us at security@scolup.qzz.io with:
- A description of the vulnerability
- Steps to reproduce it
- The potential impact
We will acknowledge your report within 48 hours and aim to provide a fix or mitigation plan as soon as possible. We will credit reporters who wish to be named, unless you prefer to remain anonymous.
Security patches are applied to the latest release only. If the latest release contains newly introduced breaking changes, we'll also apply patches to the previous release.
Linkdirecte is a student-facing SDK. Vulnerabilities involving authentication bypass, token leakage, or data exposure are treated with the highest priority.