Please do not open a public issue for suspected vulnerabilities, exposed credentials, customer data, or infrastructure details.
Report security concerns privately to support@hamavaelv.ir with the subject [SECURITY] Vulnerability report. Include:
- the affected repository, service, or component;
- a clear description of the issue and its potential impact;
- safe reproduction steps or a minimal proof of concept;
- any suggested mitigation, if available.
We aim to acknowledge valid reports within three business days and will share status updates as the issue is assessed and remediated.
Do not test against production or customer systems without written authorization. Avoid accessing, modifying, retaining, or sharing data that is not your own.
Security fixes are applied to actively maintained default branches and supported production releases. Older or archived versions may not receive updates.