SHAKEL Create your avatar

Security

Report privately.

Give maintainers a safe chance to validate and fix a vulnerability before details become public.

Private channel

Use a security advisory

Send the affected surface and commit or version, reproduction, impact, and a minimal proof through GitHub private vulnerability reporting.

Start private report ↗

Safe evidence

Share only what is needed

Use a synthetic recipe. Never include credentials, private labels, library backups, or another person’s data. Stop testing if it could disrupt the service.

Supported now

Current production and master

Before Shakel’s first public release, security fixes cover the current official deployment and current master. Old commits and independent forks are not maintained by Shakel.

What happens next

Triage, fix, then disclose

The maintainer validates and prioritizes the report, coordinates a tested fix and deployment, then publishes an advisory or release note when disclosure is safe.

Read the complete security policy ↗