Please do not report security vulnerabilities through public GitHub issues.
Instead, use one of these private channels:
- GitHub: Report a vulnerability via private vulnerability reporting
- E-Mail: jannik.mueller@caldero-systems.de
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof of concept
- The affected version or commit, and your installation method (Docker or standalone)
We will confirm receipt of your report, keep you informed about the progress, and credit you in the fix release if you wish.
Security fixes are provided for the latest release. If you run an older version, please update to the current release before reporting, as the issue may already be fixed.
artwork is self-hosted software. Issues caused purely by misconfiguration of an individual installation (e.g. exposed .env files, missing TLS) are outside the scope of this policy — but if artwork's defaults or documentation make such a misconfiguration likely, we do want to hear about it.