This policy covers every public repository in the Clawnify organization.
Please do not open a public issue for a security problem.
Report it privately in either of these ways:
- GitHub: open the repository's Security tab and choose Report a vulnerability. This starts a private advisory that only you and the maintainers can see.
- Email: security@clawnify.com
Include the repository, the version or commit, how to reproduce the problem, and what an attacker could do with it.
We acknowledge a report within 3 business days and keep you updated until it is resolved. Once a fix ships, we publish an advisory and credit you unless you ask us not to.