If you find a potential vulnerability in one of my projects, it's recommended not to report it through a standard publicly-readable issue report, in order to avoid giving possible clues to any potential attackers who could abuse it before it's fixed (see: "Just a rumour of a bug is enough to find a security exploit these days").
You can use one of these to contact me instead:
- @mackuba.eu on Bluesky (my DMs should be open, or mention me discretely with a request for contact)
- @mackuba@martianbase.net on Mastodon (my personal instance)
- email: mackuba
@protonmail.ch (optionally with this PGP key) - "Report a vulnerability" form on GitHub
I do not check my Twitter/X or LinkedIn accounts regularly.
Note: please don't submit AI-reported issues that have not been verified manually :)