10 lines
481 B
Markdown
10 lines
481 B
Markdown
# Security
|
|
|
|
Report vulnerabilities privately to the repository owner through the Gitea
|
|
security contact. Do not attach sensitive real messages to public issues.
|
|
|
|
Treat every message and attachment as hostile. The app does not execute or open
|
|
attachments, does not validate sender identity, and does not make authentication
|
|
headers trustworthy. Deploy with the documented same-origin CSP and restrictive
|
|
Permissions Policy. Supported security fixes are made on the current release.
|