Security fixes are applied to the latest released version of Busabase. Please reproduce issues against the latest release before reporting when possible.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private reporting flow:
- Open the repository's Security tab.
- Select Report a vulnerability.
- Include affected versions, impact, reproduction steps, and any suggested mitigation.
You may also contact [email protected]. We will acknowledge reports as soon as practical, investigate them privately, and coordinate disclosure and remediation with the reporter.
Never include real credentials, personal data, or secrets in a report. Use minimal test data and revoke any credential that may have been exposed.