Please report suspected security vulnerabilities privately to osakka@gmail.com with the subject Cix security report. Do not include sensitive vulnerability details in a public issue, pull request, or discussion.
This mailbox is the current maintainer-controlled security contact for Cix. It is a temporary project contact and may change as the project matures; the website and this file will be updated together if it changes.
Please include enough information to reproduce and assess the report, such as the affected Cix version or source revision, affected component, impact, reproduction steps, and any suggested mitigation. Do not send credentials, private keys, or unrelated personal data.
The maintainer will review reports privately and coordinate any fix or public disclosure where appropriate. There is currently no bug bounty, formal support commitment, or guaranteed response time. Public disclosure should wait until the maintainer has had a reasonable opportunity to assess and address the issue.
For ordinary bugs, documentation issues, and feature requests, use the public issue tracker instead.