Please do not open a public issue for security-sensitive reports.
Report vulnerabilities privately through this repository's GitHub Security Advisories.
Issues that also affect the upstream project should additionally be reported through the upstream process described by White Cornerstone.
Include:
- affected PaintNode version or commit
- operating system and architecture
- reproduction steps
- impact summary
- any relevant files, logs, or screenshots
We will acknowledge valid reports as soon as practical and coordinate fixes before public disclosure.
PaintNode is in early MVP development. For now, security fixes target the latest published release and the current main branch.