What to report
Credential exposure, release verification bypasses, hostile-data rendering bugs, unsafe egress, and webview boundary escapes.
Report vulnerabilities with enough detail to reproduce the issue without sharing unnecessary cluster secrets.
Credential exposure, release verification bypasses, hostile-data rendering bugs, unsafe egress, and webview boundary escapes.
Version, operating system, reproduction steps, expected behavior, actual behavior, and redacted evidence.
Do not send raw kubeconfigs, live tokens, private keys, or production cluster secrets.