Please don't open a public issue for a security problem.
Report it privately through GitHub Security Advisories — use the advisory form on the specific repo if the issue is in one — or email security@nexlabz.dev.
Helpful to include:
- What the issue is and roughly how bad you think it is
- Steps to reproduce, or a proof of concept
- The affected repo, version, or deployment
- Anything you think we'd get wrong about the impact
| When | What |
|---|---|
| Within 3 working days | We acknowledge your report |
| Within 10 working days | We confirm the issue and give you an assessment |
| After a fix ships | We publish an advisory and credit you, unless you'd rather we didn't |
If you don't hear from us in the first window, please chase us — a missed email is far more likely than a deliberate silence.
Anything in a public nexlabz repo, and any service we run at a nexlabz.dev domain.
Several projects here are clearly-labelled experiments rather than production software. We still want to know about problems in them, but our fix timeline will reflect what the project actually is.
Out of scope: findings from automated scanners with no demonstrated impact, missing hardening headers with no exploit path, social engineering, and anything requiring physical access to a user's machine.
Report in good faith and we won't pursue or support legal action against you. Please give us reasonable time to fix an issue before disclosing it publicly, and don't access, modify, or destroy data that isn't yours while testing.