Private channel
Use a security advisory
Send the affected surface and commit or version, reproduction, impact, and a minimal proof through GitHub private vulnerability reporting.
Start private report ↗Security
Give maintainers a safe chance to validate and fix a vulnerability before details become public.
Private channel
Send the affected surface and commit or version, reproduction, impact, and a minimal proof through GitHub private vulnerability reporting.
Start private report ↗Safe evidence
Use a synthetic recipe. Never include credentials, private labels, library backups, or another person’s data. Stop testing if it could disrupt the service.
Supported now
Before Shakel’s first public release, security fixes cover the current official deployment and current master. Old commits and independent forks are not maintained by Shakel.
What happens next
The maintainer validates and prioritizes the report, coordinates a tested fix and deployment, then publishes an advisory or release note when disclosure is safe.
Read the complete security policy ↗