Security fixes are made for the latest published version of WeekBox. Please update before reporting an issue that may already be fixed.
For a suspected vulnerability, use GitHub's private Report a vulnerability option on the WeekBox Security page when it is available. Do not publish exploit steps, private keys, or personal data in a public issue.
If private reporting is unavailable, contact a project maintainer through GitHub or the official Discord server and provide:
- The affected WeekBox version and operating system.
- Clear reproduction steps or a minimal proof of concept.
- The potential impact.
- Any suggested mitigation, if known.
We will acknowledge reports, investigate them, and publish a fix or mitigation when appropriate.