Please do not open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private vulnerability reporting:
- Go to the affected repository's Security tab.
- Click Report a vulnerability under "Advisories".
- Include as much detail as you can — affected versions, reproduction steps, and impact.
If a repo doesn't have private vulnerability reporting enabled, open a regular issue with minimal detail asking for a secure contact channel, and we'll follow up privately.
Most celladore projects are pre-1.0 and under active development. Unless a repo's own README states otherwise, only the latest version on main is supported — please update before reporting.
This is a small, active org — expect an initial response within a few days. No guaranteed SLA.