This policy covers the Nitjsefnie/Overflow repository and the deployed instance it serves.
Security fixes land on main and reach the deployed instance through the deployment procedure.
Use GitHub private vulnerability reporting. This is the only route for reporting a vulnerability. Do not open a public issue for a vulnerability, and do not disclose it publicly before a fix is available.
Test only against a local instance you run yourself. Never test against the live instance at https://overflow.nitjsefni.eu, or against other people's accounts or repositories. The live instance holds sponsors' GitHub OAuth tokens and GitLab personal access tokens.
The maintainer, Nitjsefnie, reviews the report and decides the response and any notification. The operator runbook covers operational response. There is no response-time guarantee and no bounty program.
Conduct problems go to the public tracker per CODE_OF_CONDUCT.md. How work is claimed, priced and settled is CONTRIBUTING.md's subject.