Do not open a public issue for suspected security vulnerabilities.
Use GitHub private vulnerability reporting when it is available for the
affected public repository. Otherwise, email support@swap3d.studio with:
- the affected repository, package, endpoint, or version
- a clear description of the issue and its impact
- steps or a minimal proof of concept
- any suggested mitigation
Do not include real user data, API keys, credentials, or files belonging to other users. We will acknowledge actionable reports as soon as practical and coordinate disclosure after a fix is available.
Security fixes are applied to the latest supported release. Users should upgrade to the newest published version before reporting an issue that may already be resolved.
Security reports are welcome for Swap3D public repositories, published
packages, installers, and the production service at swap3d.studio.