This policy covers every repository in the coatless-devcontainer organization that has no security policy of its own.
Please report a vulnerability privately, not in a public issue:
- through GitHub's private vulnerability reporting, where the repository's Security tab offers Report a vulnerability;
- or by e-mail to support@caffeinatedmath.com.
Say which project and version is affected, how to reproduce the problem and what an attacker gains. You should hear back within a week, and we will agree a disclosure date with you once a fix is ready.