Files
mail-tools/public/SECURITY.md
T
2026-09-01 12:39:23 +02:00

10 lines
481 B
Markdown

# Security
Report vulnerabilities privately to the repository owner through the Gitea
security contact. Do not attach sensitive real messages to public issues.
Treat every message and attachment as hostile. The app does not execute or open
attachments, does not validate sender identity, and does not make authentication
headers trustworthy. Deploy with the documented same-origin CSP and restrictive
Permissions Policy. Supported security fixes are made on the current release.