Security fixes are applied to the latest published release and the main
branch. Users should upgrade to the newest release before reporting an issue
that may already have been fixed.
Use GitHub's Security tab and select Report a vulnerability to send a private report. Do not open a public issue for an unpatched vulnerability.
Include the affected version and platform, reproduction steps or a proof of concept, the expected impact, and any suggested mitigation. Do not include production credentials, private keys, or unrelated personal data.
The maintainers will acknowledge the report, validate its scope, and coordinate a fix and disclosure timeline with the reporter. Please allow a reasonable remediation window before publishing details.
Reports about the forwarding engine, internal management channel, authentication, TLS, service installation, self-update, release artifacts, and installer are in scope. General support requests and configuration questions should use GitHub Issues.