Skip to content

Security policy

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Report them privately through GitHub’s private vulnerability reporting: go to the repository’s Security tab → Report a vulnerability.

Please include:

  • a description of the issue and its impact,
  • steps to reproduce (a proof of concept if you have one),
  • affected version or commit.

We aim to acknowledge reports within a few business days and will keep you updated on remediation. Once a fix is released we’re happy to credit you unless you’d prefer to remain anonymous.

Supported versions

Loupe is under active development; security fixes target the main branch.