Localis handles source code and may process credentials accidentally committed to a project. Security reports deserve a private channel.
For now, report a vulnerability privately to the KebiLab maintainers through GitHub's private vulnerability reporting feature on this repository. Include:
- affected version or commit;
- reproducible steps;
- expected and observed behavior;
- potential impact.
Do not include real production credentials or personal data in a report. We will acknowledge a valid report as soon as possible and coordinate disclosure after a fix is available.