Please do not open a public issue for security problems.
Email hello@iamdex.codes with:
- What the issue is and where in the code it lives
- Steps to reproduce, or a proof of concept
- What an attacker could achieve with it
You'll get an acknowledgement within 72 hours and a fix timeline once the report is confirmed. LazyPrep is maintained by a small team, so please allow reasonable time to patch before any public disclosure. Credit is given in the release notes unless you'd rather stay anonymous.
In scope:
- The LazyPrep application code in this repository
- The hosted deployment at
lazyprep.iamdex.codes - The Android app (
com.lazyprep.app)
Out of scope:
- Third-party services (Vercel, Neon, Resend, Sentry, Google) — report those to the vendor directly
- Findings that require a compromised device, a rooted phone, or physical access
- Missing hardening headers with no demonstrated impact
- Automated scanner output submitted without a working proof of concept
- Denial of service and volumetric testing — please don't
No credentials belong in this repository. .env.example is a placeholder
template only; every real value comes from the environment.
If you believe a secret has been committed, email rather than filing an issue, so it can be rotated before attention is drawn to it.