Files
mail-tools/public/SECURITY.md
T
2026-09-01 12:39:23 +02:00

481 B

Security

Report vulnerabilities privately to the repository owner through the Gitea security contact. Do not attach sensitive real messages to public issues.

Treat every message and attachment as hostile. The app does not execute or open attachments, does not validate sender identity, and does not make authentication headers trustworthy. Deploy with the documented same-origin CSP and restrictive Permissions Policy. Supported security fixes are made on the current release.