Report privately through this repository's GitHub Security Advisories ("Security" tab → "Report a vulnerability"), not a public issue or pull request.
Please include:
- the affected version or commit;
- the deployment configuration (provider, networking mode, relevant environment variables);
- a reproduction or proof of concept;
- the impact you observed.
We aim to acknowledge a report within a few business days and will coordinate disclosure with you once a fix is available.
Before reporting, read the security model for what drukbox protects, what is out of scope by design, and the tradeoffs behind each default. Findings within the documented "not vulnerabilities by design" boundary are unlikely to be treated as vulnerabilities.