Potential security issues are accepted for the latest code in the main branch and the current documented 1.0.x release line. Older snapshots may no longer receive fixes.
The project does not publish a guaranteed response or remediation time.
Do not open a public issue, discussion, or pull request containing vulnerability details, proof-of-concept material, private target information, or other security-sensitive data.
Use GitHub Security Advisories when private vulnerability reporting is available:
- Open the repository's Security Advisories page.
- Select Report a vulnerability.
- Submit the report privately.
- Wait for the maintainer to respond before publishing technical details.
If GitHub private vulnerability reporting is unavailable, use a private contact method listed on the repository owner's GitHub profile. Send only a brief request for a secure reporting channel until private communication is established.
No personal email address is published by this policy.
Provide enough information to reproduce and evaluate the issue without including unrelated sensitive data:
- Affected version, tag, or commit
- Windows and Delphi versions when relevant
- Concise description of the issue
- Minimal reproduction steps
- Potential impact
- Relevant logs or screenshots with credentials and private addresses removed
- Suggested mitigation, if known
- Test only systems and networks that you own or are explicitly authorized to use.
- Use the minimum activity required to demonstrate the issue.
- Do not access, retain, modify, or disclose third-party data.
- Do not degrade services or continue testing after confirming the issue.
- Keep vulnerability details private while the maintainer investigates and prepares a response.
Allow the maintainer reasonable time to investigate the report and prepare documentation or a fix. Coordinate the timing and content of any public disclosure through the private reporting channel.
Ordinary functional or documentation bugs that do not expose sensitive information may be submitted through the public bug-report template. Remove private IPv4 addresses, internal host names, credentials, and other confidential data before posting.