Copyright (C) 2026 devthink, nathlan, iakadion, nathu filho, allan neris, and contributors.
Saddle uses private disclosure for vulnerabilities that could expose users, credentials or third-party systems. Do not publish exploit details in a public issue before maintainers have had a reasonable opportunity to investigate and coordinate a fix. Use the repository's private security advisory channel or the contact method configured in the repository.
Security testing must be authorized by the owner of the target system. Development and CI scanning of Saddle artifacts is allowed within the project's own build and test environments. Unauthorized penetration testing, fuzzing, active scanning or credential probing of third-party systems is not allowed.
The project records accepted risks, dependency advisories and remediation status in the security documentation and workflow reports.