Skip to content

Security policy

Please report suspected vulnerabilities privately to [email protected]. Do not open a public issue with exploit details or sensitive data before the report has been reviewed.

Include the affected FastSprout version, a minimal reproduction, the expected impact, and a way to contact you. You can redact secrets and personal data from your report. We will acknowledge the report and coordinate disclosure and a fix with you.

The latest release and the development branch are the versions considered for security fixes. Earlier releases do not have a published support window.