Security
Keep vulnerability details private.
Use GitHub private vulnerability reporting for suspected vulnerabilities in Ghostbuild. Do not open a public support, abuse, or bug issue with exploit details.
Private reporting
Report a vulnerability privately
Include the affected component, impact, reproduction steps or proof of concept, and a suggested mitigation if available. Remove credentials, personal data, and third-party secrets.
Response and disclosure
Ghostbuild does not promise a response time during public beta. If the owner responds, disclosure will be coordinated after an appropriate fix is available.
Public beta channel limits
Support and abuse use public GitHub issues for non-sensitive reports. Security vulnerabilities use GitHub private vulnerability reporting. No response-time commitment is offered during public beta. Do not rely on this channel for an emergency response.