LocalCompose uses GitHub Security Advisories for confidential security reporting. To report a security vulnerability:
- Navigate to our Security Advisories page: Submit Security Advisory
- Only the security team can see and triage your submission.
- Please do not report vulnerabilities in public issues, pull requests, or discussions.
- Tip for community reporters: Keep the link provided after submission to review or update your report. If you lose the link or cannot access your original submission, submitting a new advisory with updated information is welcome. The security team values updates from community reporters to help triage and resolve vulnerabilities.
- Only submit issues that represent genuine security vulnerabilities.
- Provide as much detail as possible to reproduce the issue safely.
- The security team will review, triage, and coordinate fixes privately.
- Once resolved, advisories may be disclosed publicly with fixes.