Security¶
If you find a potential security vulnerability in Zensical or another project we maintain, report it privately – even if you are unsure whether it is security-sensitive.
Report security vulnerabilities privately
Do not open a public GitHub issue, pull request, or discussion, and do not share the vulnerability in Discord or Zensical Spark. Email us at hello@zensical.org instead.
What to include¶
There is no fixed template. In your first email, share whatever you can about the affected project and version, what you observed and its potential impact, and how we can reproduce it. Include a minimal proof of concept or relevant supporting material if available.
Do not send credentials, secrets, private customer content, or other sensitive data by email. Tell us what additional material is available so we can agree on an appropriate way to share it.
What to expect¶
We will acknowledge your report within three business days and begin our review. We may ask follow-up questions or arrange another way to receive sensitive material, and we will keep you updated as the investigation proceeds.
Please keep the details private until we have addressed the vulnerability and coordinated its disclosure with you. We are happy to credit your contribution after the issue has been resolved.
If the vulnerability is in a third-party dependency, report it directly to the maintainers of that project. If you are unsure where the vulnerability belongs, email us and we will help route it.