Most repositories in this organisation track a single rolling branch
(usually main). Unless a repository's own SECURITY.md says otherwise,
only the latest commit on the default branch is supported with security
fixes.
Please do not open a public issue for security vulnerabilities.
Instead, report it privately using one of the following:
- Preferably, use GitHub's private vulnerability reporting on the affected repository (Security tab → "Report a vulnerability"), if enabled.
- Otherwise, email security@planet-community.org with details of the issue.
Please include, where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof of concept
- Affected repository, version/commit, and configuration
We aim to acknowledge reports within 7 days. As this is a volunteer-run community organisation, response and fix timelines are best-effort.
Please give us a reasonable amount of time to address the issue before any public disclosure.