Thanks for helping keep Rogallo safe.
Rogallo is a solo-maintained project, so security fixes are handled on a best-effort basis.
Please report issues against the latest code on the main branch.
If you think you found a security issue, please do not open a public issue.
Please report it privately through GitHub’s private vulnerability reporting
Please include:
- What you found
- How to reproduce it
- What version/commit you tested
- Any idea of impact
I’ll do my best to:
- Acknowledge your report within a couple or so days
- Confirm whether it’s a real vulnerability
- Fix it and publish a patch when possible
- Credit you publicly (if you want)
Because this is a spare-time project, response/fix times will vary.
Useful reports usually involve things like:
- Command execution/injection risks
- Unsafe handling of remote/untrusted content
- Accidental credential or token exposure
- Dependency issues with real-world impact