Do not report security vulnerabilities through public GitHub Issues, pull requests, or discussions. Public disclosure can expose users before a report can be assessed.
Send a private report to security@revus.org.
Please include, when available:
- A clear description of the vulnerability
- Reproduction steps or a proof of concept that can be shared safely
- Potential impact
- Affected Revus version or versions
- Relevant logs or screenshots with sensitive data removed
- A suggested remediation or mitigation
Do not include passwords, access tokens, private keys, or unrelated personal information in a report. If a sensitive attachment is necessary, describe it first and wait for instructions about a safe transfer method.
There is no guaranteed response or remediation deadline. The maintainers will assess reports as information and capacity allow.
If an issue may contain security-sensitive information, stop editing the public report and contact the private address above. Do not copy vulnerability details into a public issue while requesting help.