Do not disclose suspected vulnerabilities in public issues, discussions, pull requests, or social media posts.
Email security@codevelo.dev with the subject
Security report. Include:
- the affected repository, component, or URL;
- a clear description of the issue and potential impact;
- reproduction steps or a proof of concept when safe to provide;
- any suggested mitigation; and
- a secure way to contact you.
Do not access, modify, retain, or share data that does not belong to you. Avoid actions that could disrupt services or degrade availability.
CodeVelo will acknowledge the report, assess its scope, and coordinate remediation and disclosure when appropriate. Response times depend on severity and available evidence.
Each public repository documents its supported versions or release status. Unless a repository states otherwise, only the current default branch is actively reviewed.