Cybrense IT Services takes the security of its open-source projects seriously.
Please do not open a public issue for a suspected vulnerability.
Use one of these private channels:
- Use the repository's Security tab and private vulnerability reporting form when it is available.
- Email contact@cybrense.com with the subject
[SECURITY] <project name>: <short summary>.
Include, when possible:
- the affected repository, component, and version or commit;
- a clear description of the issue and its potential impact;
- steps to reproduce or a minimal proof of concept;
- any known mitigations;
- a safe way to contact you for follow-up.
Do not include real credentials, personal data, or production secrets in the report. Use sanitized examples.
We will acknowledge the report as soon as practical, validate the issue, and coordinate next steps. Please allow time for a fix and release before public disclosure.
This policy applies to actively maintained public repositories in the Cybrense IT Services organization. Third-party services and upstream dependencies are governed by their own security policies, but we welcome reports showing how they affect a Cybrense project.