Report security issues in this repository through a private GitHub security advisory:
https://github.com/tortuvshin/open-apps/security/advisories/new
Do not open a public issue for an undisclosed vulnerability. You may also contact an active maintainer using the email address in repository commit metadata.
We aim to acknowledge reports within three working days, provide a triage update within seven, and agree on a disclosure timeline with the reporter.
The Astro application, Grove integration, GitHub Actions, deployment
configuration, and committed dependencies are in scope. The apps listed in
data/records/ are external projects; report vulnerabilities in those apps to
their own maintainers.
Only the latest commit on main receives security fixes.