Skip to content

Security policy

Canonical GitHub source · Pulled from SECURITY.md at ref main during this site build. Use Edit this page below to suggest a correction at the source.

Security fixes target the latest published Brand Navigation release and the maintained d-compat/<YYYY>.<M> branches documented in the testing record. Older commits and unsupported Discourse versions may not receive fixes.

Report suspected vulnerabilities privately to security@codeworkslabs.dev. The mailbox is monitored by CodeWorksLabs.

Include the affected Brand Navigation release, branch, or commit; the Discourse version; a description of the impact; and reproducible steps or a minimal proof of concept where safe. Do not include credentials, personal data, production secrets, or unrelated private information.

Do not open a public GitHub issue for a vulnerability that has not been disclosed safely. CodeWorksLabs will confirm receipt, assess the report, and coordinate remediation and disclosure with the reporter as appropriate.

Use GitHub Issues for non-sensitive bugs, compatibility reports, configuration questions, and feature requests.