Security policy

August 16, 2026 ยท View on GitHub

Supported versions

The project has no stable release yet. Security fixes currently target the default branch and the latest tagged release once releases begin.

Reporting a vulnerability

GitHub private vulnerability reporting is not currently enabled for this repository. Until it is enabled and verified, email contact@mosesmawila.de with the subject THE LOOP security report. Include the affected version, reproduction steps, impact and any proposed mitigation. Do not attach live secrets; coordinate a safe transfer method first if sensitive evidence is necessary.

Do not open a public issue for a vulnerability. Do not include live credentials, customer data or private infrastructure details in a report. Use synthetic or redacted evidence wherever possible.

The maintainer will acknowledge a complete report when it is reviewed. Response and disclosure timing depend on severity and whether the issue affects an unreleased specification or shipped code.