Security policy
Reporting a vulnerability
Please do not open a public issue for security vulnerabilities.
Report them privately through GitHub’s private vulnerability reporting: go to the repository’s Security tab → Report a vulnerability.
Please include:
- a description of the issue and its impact,
- steps to reproduce (a proof of concept if you have one),
- affected version or commit.
We aim to acknowledge reports within a few business days and will keep you updated on remediation. Once a fix is released we’re happy to credit you unless you’d prefer to remain anonymous.
Supported versions
Loupe is under active development; security fixes target the main branch.