Security fixes are applied to the latest release and the main branch.
| Version | Supported |
|---|---|
| Latest release | Yes |
main |
Yes |
| Older releases | No |
Please do not open a public issue for a suspected vulnerability.
Send a private report to ignaziodesantisofficial@gmail.com with:
- the affected endpoint, component, or commit;
- clear reproduction steps or a proof of concept;
- the security impact you expect;
- any suggested mitigation, if you have one.
You should receive an acknowledgement within five business days. Please allow time for the issue to be investigated and patched before publishing details.
Reports about authentication bypasses, tenant isolation, secret exposure, injection, dependency vulnerabilities, and unsafe default configurations are especially useful.
Operational security for deployments built from this starter—including TLS, secret management, network policy, rate limiting, and database backups—remains the deploying team's responsibility.