If you discover a security vulnerability in DataPilot, please do not open a public GitHub issue. Instead, report it privately via GitHub's private security advisory feature or by contacting the maintainer directly through LinkedIn.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce
- Any relevant logs or proof-of-concept code
This project handles Salesforce connection credentials (username/password, OAuth client secrets, security tokens). If you find an issue related to how credentials are stored, encrypted, or transmitted, please treat it as high priority.
Only the latest release on master receives security fixes.