Pubky Locks is pre-production software. Interfaces, persistence formats, and operational assumptions may change without migration support. Do not rely on it to protect valuable private content or real funds without an independent security and operational review.
Do not report suspected vulnerabilities, leaked credentials, private identities, recovery material, bearer credentials, or exploit details in a public issue.
Use GitHub's private vulnerability reporting for this repository:
https://github.com/pubky/locks/security/advisories/new
Include the affected revision, impact, reproduction steps, and any suggested mitigation. Minimize sensitive data and use disposable test identities.
If private vulnerability reporting is unavailable, contact a repository maintainer privately and ask for a secure reporting channel before sharing details.
Only the latest revision of the default branch is considered for security fixes. There are no supported releases yet.
Please allow maintainers time to reproduce, remediate, and coordinate disclosure. No response-time or bounty commitment is currently offered.