If the affected project has its own security policy, follow that policy. This guide is the fallback for FGLabs repositories without project-specific instructions.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature when the repository provides it. Otherwise, email support@fglabs.dev with a subject beginning Security report: followed by the project name.
Include the affected version, a description of the issue, reproduction steps or a minimal proof of concept, and the potential impact. Remove credentials and personal data. Do not attach live secrets, customer backups, or sensitive production files; ask for an appropriate way to share additional evidence if needed.
Please allow time to investigate and coordinate a fix before publishing details. There is no guaranteed response time or paid bug bounty unless a project explicitly states otherwise.
Supported versions and security update availability are defined by each project's policy and releases. This organization-level guide does not extend support to every historical release.