# Security Policy ## How To Report a Vulnerability If you find a potential vulnerability in one of my projects, it's recommended not to report it through a standard publicly-readable issue report, in order to avoid giving possible clues to any potential attackers who could abuse it before it's fixed (see: ["Just a rumour of a bug is enough to find a security exploit these days"](https://anil.recoil.org/notes/rumour-is-the-exploit)). You can use one of these to contact me instead: - [@mackuba.eu](https://bsky.app/profile/did:plc:oio4hkxaop4ao4wz2pp3f4cr) on Bluesky (my DMs should be open, or mention me discretely with a request for contact) - [@mackuba@martianbase.net](https://martianbase.net/@mackuba) on Mastodon (my personal instance) - email: mackuba `@` protonmail.ch (optionally with [this PGP key](https://mail-api.proton.me/pks/lookup?op=get&search=mackuba@protonmail.ch)) - "Report a vulnerability" form in the project's GitHub repo (if it is on GitHub) I do not check my Twitter/X or LinkedIn accounts regularly. Note: please don't submit AI-reported issues that have not been verified manually :)